Out-of-Bounds Write Vulnerability in Linux Kernel Affecting IPv6 Processing
CVE-2026-89783

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
16 September 2026

What is CVE-2026-89783?

A vulnerability in the Linux kernel's IPv6 processing component could lead to an out-of-bounds write when handling security path data. In certain conditions, the depth check in xfrm6_input_addr() erroneously allows an attempt to write beyond the allocated array, risking system stability. This flaw could potentially be exploited by sending specially crafted network packets, resulting in erratic behavior or crashes due to violation of array boundaries. Proper validation checks have been implemented to address this issue and enhance system reliability against such exploit attempts.

Affected Version(s)

Linux 9473e1f631de339c50bde1e3bd09e1045fe90fd5 < 91fc387f63c00ddfb5221127a17bac97549a8343

Linux 9473e1f631de339c50bde1e3bd09e1045fe90fd5 < 68e8737fe8e72f085c608cff322b3d2de8340af1

Linux 9473e1f631de339c50bde1e3bd09e1045fe90fd5 < 8fe2c53fb81f5ad5be43af2ad09583f7c78b4b77

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.