Out-of-Bounds Read Vulnerability in Linux Kernel Affecting Multiple Devices
CVE-2026-89743

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
11 September 2026

What is CVE-2026-89743?

The Linux kernel has a vulnerability related to the NSM device where it fails to properly limit the length of the response stored in memory, allowing a malicious backend to report an excessive length. This oversight can lead to an out-of-bounds read, potentially exposing adjacent kernel heap memory to user space, which could result in unintended data disclosure. While well-behaved devices should not present any issues, inadequate checks in the response handling can compromise system security and integrity.

Affected Version(s)

Linux b9873755a6c8ccfce79094c4dce9efa3ecb1a749 < 339f19b9a6171289b0e797deb8bda80b9a1fcc30

Linux b9873755a6c8ccfce79094c4dce9efa3ecb1a749 < 29e634a18957acda11383a15ab98a91c4ae9e294

Linux b9873755a6c8ccfce79094c4dce9efa3ecb1a749 < 2aa0fb9c96f894a9c179a48e7522ea6705800adf

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.