NULL pointer dereference in Linux kernel - CVE-2026-89511
Published: September 12, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a null pointer dereference in the qede driver's TPA fragment processing when handling TPA continuation fragments under memory pressure. A remote attacker can send network traffic that is processed as TPA continuation fragments during memory pressure to cause a denial of service.