Improper Validation of Specified Quantity in Input in Linux kernel - CVE-2026-89480

 

Improper Validation of Specified Quantity in Input in Linux kernel - CVE-2026-89480

Published: September 12, 2026


Vulnerability identifier: #VU149330
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-89480
CWE-ID: CWE-1284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper validation of the received data length in the NVMe/TCP host driver when processing a short C2HData PDU from an NVMe/TCP controller. A remote attacker can respond to a read request with fewer bytes than requested to disclose sensitive information.


Affected software

Linux kernel
Red Hat Enterprise Linux for Real Time
Red Hat Enterprise Linux for Real Time for NFV
kernel-rt (Red Hat package)

How to mitigate CVE-2026-89480

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3
kernel-rt (Red Hat package) - update to 4.18.0-553.168.1.rt7.509.el8_10

External References

Related Security Bulletins