{"id":"CVE-2026-89511","title":"kernel: qede: Fix NULL pointer dereference in TPA fragment processing (CVE-2026-89511)","summary":"A flaw was found in the qede driver in the Linux kernel. Under specific memory pressure conditions, the driver can encounter a NULL pointer dereference when processing network traffic using TPA (TCP Segmentation Offload) continuation fragm…","severity":"medium","cvss":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","cvssSource":"vendor","cwe":"CWE-476","vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","affected":["enterprise_linux 10","enterprise_linux 7","enterprise_linux 8","enterprise_linux 9","openshift_container_platform 4"],"published":"2026-09-11","updated":"2026-09-18","sourceUpdated":"2026-09-18T12:49:08+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89511.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89511.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-89511"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2532100"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-89511"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89511"},{"url":"https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-89511.mbox"},{"url":"https://git.kernel.org/stable/c/e2214e2793154b745436e46c6a9a7985d9b3781d"},{"url":"https://git.kernel.org/stable/c/dd8bc0a9d87d2b048711edd17ba7286432edd285"},{"url":"https://git.kernel.org/stable/c/fa7c9bd2c4a8de167e2fb32968ca4d91dd774375"},{"url":"https://git.kernel.org/stable/c/a5e1fdc126ab337d601d1a00cc4b47910679d005"},{"url":"https://git.kernel.org/stable/c/7f911e208b3ca2c76d9f2bbba1f54b9403568c10"},{"url":"https://git.kernel.org/stable/c/2a952fb1b20d83e83ca852773e6188511f7d2191"},{"url":"https://git.kernel.org/stable/c/f5c8619ccbd70102642120c4c6fda1c048a555fd"},{"url":"https://git.kernel.org/stable/c/06aa3d26327f24edd039ff249672fdf6f2ba5695"}],"tags":["csaf","vex","red-hat","cve.org","score-dispute"],"epss":0.00716,"epssPercentile":0.51905,"scores":{"vendor":5.5,"cna":7.5},"ingestedAt":"2026-09-14T15:23:07.452Z","slug":"CVE-2026-89511","body":"## Overview\n\nA flaw was found in the qede driver in the Linux kernel. Under specific memory pressure conditions, the driver can encounter a NULL pointer dereference when processing network traffic using TPA (TCP Segmentation Offload) continuation fragments. This issue stems from an uninitialized data pointer, which can lead to the system attempting to use an invalid memory page. Consequently, this can trigger a kernel panic, causing a Denial of Service (DoS) for the affected system.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4 · no fix planned: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, … · updated 2026-09-18 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89511.json)\n\n**kernel: qede: Fix NULL pointer dereference in TPA fragment processing** — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-18.\n\nAffected:\n\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 7\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n\nNo fix planned:\n\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 7\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n\nNot affected:\n\n- Red Hat Enterprise Linux 6\n\n## Remediation\n\nFix deferred","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":30.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[{"seq":206938,"id":"CVE-2026-89511","ts":1789749708703,"field":"cvss","old":"7.5","new":"5.5"},{"seq":206937,"id":"CVE-2026-89511","ts":1789749708703,"field":"severity","old":"high","new":"medium"},{"seq":197992,"id":"CVE-2026-89511","ts":1789384321286,"field":"cvss","old":"5.9","new":"7.5"},{"seq":197991,"id":"CVE-2026-89511","ts":1789384321286,"field":"severity","old":"medium","new":"high"},{"seq":183803,"id":"CVE-2026-89511","ts":1789356677459,"field":"cvss","old":"7.5","new":"5.9"},{"seq":183802,"id":"CVE-2026-89511","ts":1789356677459,"field":"severity","old":"high","new":"medium"},{"seq":153304,"id":"CVE-2026-89511","ts":1789285349963,"field":"cvss","old":null,"new":"7.5"},{"seq":153303,"id":"CVE-2026-89511","ts":1789285349963,"field":"severity","old":"none","new":"high"},{"seq":147776,"id":"CVE-2026-89511","ts":1789270212245,"field":"cvss","old":null,"new":"5.9"},{"seq":147775,"id":"CVE-2026-89511","ts":1789270212245,"field":"severity","old":"none","new":"medium"},{"seq":109528,"id":"CVE-2026-89511","ts":1789183732293,"field":"cvss","old":null,"new":"5.9"},{"seq":109527,"id":"CVE-2026-89511","ts":1789183732293,"field":"severity","old":"none","new":"medium"}]}