CVE-2026-89533
A flaw in the Linux kernel’s RDMA read handling can cause incorrect DMA lengths and a u32 underflow, potentially leading to large memory allocations and kernel crashes. The issue was fixed in the kernel source. It is considered critical because it can be triggered remotely without any user interaction.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
All Linux systems running kernel versions that contain the vulnerable RDMA read code – i.e., any distribution that has not yet applied the kernel update that fixes CVE‑2026‑89533.
Real-world impact
An attacker could trigger the bug to cause a kernel panic or denial‑of‑service, and in some scenarios could lead to arbitrary code execution or privilege escalation on the affected system.
Why this severity
The CVSS score of 9.8 reflects that the vulnerability can be exploited over the network with low effort, requires no privileges or user interaction, and compromises confidentiality, integrity, and availability of the system.
What to do about it
- 01Upgrade the Linux kernel to a version that includes the CVE‑2026‑89533 fix.
- 02Reboot the system so the new kernel is loaded.
NVD description indicates the kernel has resolved the issue.
Timeline
- Sep 11, 2026 · 2d agoPublishedDisclosed and added to the National Vulnerability Database.
- Sep 13, 2026 · 7h agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.