Integer underflow in Linux kernel - CVE-2026-89476

 

Integer underflow in Linux kernel - CVE-2026-89476

Published: September 12, 2026


Vulnerability identifier: #VU149341
CSH Severity: Low
CVSS v4: 0 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-89476
CWE-ID: CWE-191
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause an integer underflow.

The vulnerability exists due to improper tracking of outstanding stream reconfiguration request parameters in SCTP stream reconfiguration response handling when processing duplicate RECONF responses. A remote attacker can send duplicate RECONF responses to cause an integer underflow.

A cached RECONF chunk containing multiple request parameters must have another parameter still outstanding.


Affected software

Linux kernel

How to mitigate CVE-2026-89476

Install security update from vendor's repository.


External References

Related Security Bulletins