Improper input validation in Linux kernel - CVE-2026-89481
Published: September 12, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper input validation in nvme_tcp_handle_r2t() when processing an R2T request for a read command. A remote attacker can send an R2T request for a read command to disclose sensitive information.
The disclosed read destination buffer may contain stale kernel data.