Vulnary
← back to the feed
Critical· 9.8official fix available

CVE-2026-89526

CVE-2026-89526 is a critical, remotely triggered flaw in the Linux kernel's RPC/RDMA server. A low-complexity attack requiring no prior privileges or user interaction can send malformed Read-chunk positions that cause the kernel to read or copy beyond the intended receive buffer, potentially exposing adjacent memory and affecting data integrity and availability.

publishedSep 11, 2026
last modifiedSep 13, 2026
sourcesNVD
severity · cvss
9.8
critical · how bad it is
exploitation · epss
<1%
10th percentile · chance of exploitation in 30 days
(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
auto-deletes from the system
counting…on Oct 13, 2026

An official fix is available, so this entry is kept for 30 days and then removed automatically.

01

Who is affected

Users of affected Linux kernel versions that include the vulnerable RPC/RDMA server code. No affected products are listed in the supplied data.

02

Real-world impact

Potential exposure of adjacent memory and disruption of affected systems.

03

Why this severity

The issue has a CVSS score of 9.8 and can affect confidentiality, integrity, and availability.

04

What to do about it

official fix available
recommended steps
  1. 011. Apply the Linux kernel update containing the svcrdma Read-chunk position validation fix.

The NVD description states that the Linux kernel vulnerability has been resolved, but it does not provide an affected version or patch number.

05

Timeline

  1. Sep 11, 2026 · 2d ago
    Published
    Disclosed and added to the National Vulnerability Database.
  2. Sep 13, 2026 · 7h ago
    Official fix available
    A vendor patch or mitigation now exists — see the remediation steps above.
06

How it’s attacked

Attack vectorNetwork (remote)
Attack complexityLow
Privileges requiredNone
User interactionNone needed
ScopeUnchanged
Confidentiality impactHigh
Integrity impactHigh
Availability impactHigh
07

References & advisories

(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →