{"id":"CVE-2026-89481","title":"kernel: nvme-tcp: fix host memory disclosure on R2T for a read command (CVE-2026-89481)","summary":"A flaw was found in the Linux kernel's NVMe (Non-Volatile Memory Express) over TCP (nvme-tcp) component. A malicious NVMe controller can exploit this vulnerability by sending a Ready to Transfer (R2T) command for a read request. The host s…","severity":"high","cvss":7,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","cvssSource":"vendor","cwe":"CWE-201","vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","affected":["enterprise_linux 10","enterprise_linux 8","enterprise_linux 9","openshift_container_platform 4"],"published":"2026-09-11","updated":"2026-09-18","sourceUpdated":"2026-09-18T09:49:46+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89481.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89481.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-89481"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2532184"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-89481"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89481"},{"url":"https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-89481.mbox"},{"url":"https://git.kernel.org/stable/c/49a4dcf57608ebf6432dbcb203ed25e7ed581445"},{"url":"https://git.kernel.org/stable/c/bc4013c7cce58d46f792c8c87bc8c8318a70190e"},{"url":"https://git.kernel.org/stable/c/a4c3c7310156493797c920b10d8648c07aa05403"},{"url":"https://git.kernel.org/stable/c/3b3d27670c0c890ba7cf1bc3614cab61bde6d25c"},{"url":"https://git.kernel.org/stable/c/3a0b05145053a5fad1a2ddb4e4d87b07385e63e5"},{"url":"https://git.kernel.org/stable/c/6efbc52237facda35d2d874fe1765bb4839275d8"}],"tags":["csaf","vex","red-hat","cve.org"],"epss":0.00413,"epssPercentile":0.35134,"scores":{"vendor":7,"cna":7.5},"ingestedAt":"2026-09-14T15:23:07.453Z","slug":"CVE-2026-89481","body":"## Overview\n\nA flaw was found in the Linux kernel's NVMe (Non-Volatile Memory Express) over TCP (nvme-tcp) component. A malicious NVMe controller can exploit this vulnerability by sending a Ready to Transfer (R2T) command for a read request. The host system, failing to properly validate the request direction, will then send the contents of its read destination buffer to the controller. This can lead to the disclosure of stale kernel memory data, potentially revealing sensitive information.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Important · affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4 · no fix planned: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4 · updated 2026-09-18 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89481.json)\n\n**kernel: nvme-tcp: fix host memory disclosure on R2T for a read command** — rated Important by Red Hat. Released 2026-09-11, updated 2026-09-18.\n\nAffected:\n\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n\nNo fix planned:\n\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n\nNot affected:\n\n- Red Hat Enterprise Linux 6\n- Red Hat Enterprise Linux 7\n\n## Remediation\n\nAffected","depth":"twilight","depthScore":39,"depthScoreParts":{"impact":38.5,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[{"seq":206960,"id":"CVE-2026-89481","ts":1789749719391,"field":"cvss","old":"7.5","new":"7"},{"seq":198024,"id":"CVE-2026-89481","ts":1789384321439,"field":"cvss","old":"7.4","new":"7.5"},{"seq":183529,"id":"CVE-2026-89481","ts":1789356675755,"field":"cvss","old":"7.5","new":"7.4"},{"seq":153262,"id":"CVE-2026-89481","ts":1789285349788,"field":"cvss","old":null,"new":"7.5"},{"seq":153261,"id":"CVE-2026-89481","ts":1789285349788,"field":"severity","old":"none","new":"high"},{"seq":147616,"id":"CVE-2026-89481","ts":1789270211609,"field":"cvss","old":null,"new":"7.4"},{"seq":147615,"id":"CVE-2026-89481","ts":1789270211609,"field":"severity","old":"none","new":"high"},{"seq":109370,"id":"CVE-2026-89481","ts":1789183731645,"field":"cvss","old":null,"new":"7.4"},{"seq":109369,"id":"CVE-2026-89481","ts":1789183731645,"field":"severity","old":"none","new":"high"}]}