OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-89969

CRITICAL · CVSS 9.8 EPSS 0.76%

Source: NVD + CISA KEV + EPSS · Published 2026-09-16 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

The vulnerability in the Linux kernel affects the nvmet-tcp component, allowing an out-of-bounds write due to improper handling of Protocol Data Units (PDUs). An attacker can exploit this flaw to corrupt adjacent kernel memory by sending specially crafted requests, which could lead to system instability or unauthorized access. Organizations using affected Linux systems, particularly those relying on nvmet-tcp for storage networking, should prioritize patching this vulnerability to mitigate potential risks.

CVE
CVE-2026-89969
Severity
CRITICAL
CVSS
9.8
EPSS
0.76%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: fix out-of-bounds write when receiving an over-long PDU nvmet_tcp_try_recv_pdu() reads a PDU header into the fixed 128-byte queue->pdu union, then computes the remaining payload length as queue->left = hdr->hlen - queue->offset + hdgst; and reads that many more bytes into &queue->pdu + queue->offset, without ever bounding the result against sizeof(queue->pdu). A struct nvme_tcp_icreq_pdu is itself 128 bytes, exactly the size of the union. Once a header digest has been negotiated (hdgst = 4), a second ICReq passes the hlen == nvmet_tcp_pdu_size() check but yields queue->left = 128 - 8 + 4 = 124, so bytes 8..132 are written into the 128-byte buffer -- 4 bytes past its end, over queue->hdr_digest and queue->data_digest. Those bytes are attacker-controlled (an ICReq carries no digest), and the duplicate ICReq is only rejected later, after the overflow. A remote unauthenticated host can thus corrupt kernel memory adjacent to the receive buffer. Reject any PDU whose declared length would read past the end of queue->pdu before the second recv.