Out-of-bounds write in Linux kernel - CVE-2026-89482
Published: September 12, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper validation of C2HData requests in the NVMe/TCP receive path when handling C2HData for a WRITE_ZEROES command with a residual iterator on the same tag. A remote attacker can send a C2HData request to trigger a wild memory write and cause a denial of service.