{"id":"CVE-2026-89551","title":"kernel: SUNRPC: xdr_buf_trim: clamp buf->len to avoid underflow (CVE-2026-89551)","summary":"A flaw was found in the Linux kernel's SUNRPC subsystem, specifically within the `xdr_buf_trim()` function. This vulnerability occurs when `xdr_buf_trim()` attempts to reduce the size of an XDR buffer. If the buffer's length is smaller tha…","severity":"high","cvss":7,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","cvssSource":"vendor","cwe":"CWE-191","vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","affected":["enterprise_linux 10","enterprise_linux 6","enterprise_linux 7","enterprise_linux 8","enterprise_linux 9","openshift_container_platform 4"],"published":"2026-09-11","updated":"2026-09-16","sourceUpdated":"2026-09-16T14:14:55+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89551.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89551.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-89551"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2532375"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-89551"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89551"},{"url":"https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-89551.mbox"},{"url":"https://git.kernel.org/stable/c/a3d77bcd974b8625d16bddf448cb3a1b5e37049c"},{"url":"https://git.kernel.org/stable/c/fa16bbe987b47e771e52eeb1b4540f18d92496ac"},{"url":"https://git.kernel.org/stable/c/a924ac4c78afab71bf82641afa3b62e0c4a8b55e"},{"url":"https://git.kernel.org/stable/c/4bf59cb0ea5b0ddfbc46a1dc2fa78fc8b9986ce4"},{"url":"https://git.kernel.org/stable/c/e6267cccd7b05cc514e57f2160aa8db85f5c2701"},{"url":"https://git.kernel.org/stable/c/ad0cce80d4af2f74674e8b635d97aa3880e83da8"},{"url":"https://git.kernel.org/stable/c/85e9602650e9df07190abe817cee3b4d9bc3df17"},{"url":"https://git.kernel.org/stable/c/3f491306dcb673ff5e78e1044ba450c58978774e"}],"tags":["csaf","vex","red-hat","cve.org","score-dispute"],"epss":0.00755,"epssPercentile":0.5312,"scores":{"vendor":7,"cna":9.8},"ingestedAt":"2026-09-14T15:23:07.452Z","slug":"CVE-2026-89551","body":"## Overview\n\nA flaw was found in the Linux kernel's SUNRPC subsystem, specifically within the `xdr_buf_trim()` function. This vulnerability occurs when `xdr_buf_trim()` attempts to reduce the size of an XDR buffer. If the buffer's length is smaller than the amount being trimmed, an integer underflow can occur, causing the buffer's length to wrap to a very large value. This corrupted length then propagates to other XDR decoders, potentially leading to data misinterpretation and unexpected system behavior.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4 · no fix planned: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, … · updated 2026-09-16 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89551.json)\n\n**kernel: SUNRPC: xdr_buf_trim: clamp buf->len to avoid underflow** — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-16.\n\nAffected:\n\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 6\n- Red Hat Enterprise Linux 7\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n\nNo fix planned:\n\n- Red Hat Enterprise Linux 6\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 7\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n\n## Remediation\n\nOut of support scope","depth":"twilight","depthScore":39,"depthScoreParts":{"impact":38.5,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[{"seq":205440,"id":"CVE-2026-89551","ts":1789576714072,"field":"cvss","old":"9.8","new":"7"},{"seq":205439,"id":"CVE-2026-89551","ts":1789576714072,"field":"severity","old":"critical","new":"high"},{"seq":197935,"id":"CVE-2026-89551","ts":1789384321031,"field":"cvss","old":"7.4","new":"9.8"},{"seq":197934,"id":"CVE-2026-89551","ts":1789384321031,"field":"severity","old":"high","new":"critical"},{"seq":183744,"id":"CVE-2026-89551","ts":1789356677206,"field":"cvss","old":"9.8","new":"7.4"},{"seq":183743,"id":"CVE-2026-89551","ts":1789356677206,"field":"severity","old":"critical","new":"high"},{"seq":153358,"id":"CVE-2026-89551","ts":1789285350188,"field":"cvss","old":null,"new":"9.8"},{"seq":153357,"id":"CVE-2026-89551","ts":1789285350188,"field":"severity","old":"none","new":"critical"},{"seq":147323,"id":"CVE-2026-89551","ts":1789270209730,"field":"cvss","old":null,"new":"7.4"},{"seq":147322,"id":"CVE-2026-89551","ts":1789270209730,"field":"severity","old":"none","new":"high"},{"seq":109076,"id":"CVE-2026-89551","ts":1789183730213,"field":"cvss","old":null,"new":"7.4"},{"seq":109075,"id":"CVE-2026-89551","ts":1789183730213,"field":"severity","old":"none","new":"high"}]}