CVE-2026-89526
CVE-2026-89526 is a critical, remotely triggered flaw in the Linux kernel's RPC/RDMA server. A low-complexity attack requiring no prior privileges or user interaction can send malformed Read-chunk positions that cause the kernel to read or copy beyond the intended receive buffer, potentially exposing adjacent memory and affecting data integrity and availability.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Users of affected Linux kernel versions that include the vulnerable RPC/RDMA server code. No affected products are listed in the supplied data.
Real-world impact
Potential exposure of adjacent memory and disruption of affected systems.
Why this severity
The issue has a CVSS score of 9.8 and can affect confidentiality, integrity, and availability.
What to do about it
- 011. Apply the Linux kernel update containing the svcrdma Read-chunk position validation fix.
The NVD description states that the Linux kernel vulnerability has been resolved, but it does not provide an affected version or patch number.
Timeline
- Sep 11, 2026 · 2d agoPublishedDisclosed and added to the National Vulnerability Database.
- Sep 13, 2026 · 7h agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.