{"id":"CVE-2026-89552","title":"kernel: Linux kernel: Denial of Service via NULL pointer dereference in parameter handling (CVE-2026-89552)","summary":"A flaw was found in the Linux kernel. When updating charp parameters, an allocation failure can cause the parameter to be set to NULL before the new value is successfully allocated. This can lead to a kernel NULL pointer dereference, which…","severity":"medium","cvss":4.1,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H","cvssSource":"vendor","cwe":"CWE-476","vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","affected":["openshift_container_platform 4"],"published":"2026-09-11","updated":"2026-09-15","sourceUpdated":"2026-09-15T04:57:48+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89552.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89552.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-89552"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2532253"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-89552"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89552"},{"url":"https://git.kernel.org/stable/c/0d8e2404925a0607ffec79a53170715a46936896"},{"url":"https://git.kernel.org/stable/c/3dfaae04243cde460d82dfc2a7dd0bb6664d20ae"},{"url":"https://git.kernel.org/stable/c/614f873268c5b172804c9af6639bd17b7e1e2359"},{"url":"https://git.kernel.org/stable/c/704ecd010d4a9b33160e40b74eb402f6b86a18e0"}],"tags":["csaf","vex","red-hat","cve.org"],"epss":0.00168,"epssPercentile":0.06454,"ingestedAt":"2026-09-14T11:11:19.886Z","slug":"CVE-2026-89552","body":"## Overview\n\nA flaw was found in the Linux kernel. When updating charp parameters, an allocation failure can cause the parameter to be set to NULL before the new value is successfully allocated. This can lead to a kernel NULL pointer dereference, which may result in a system crash and a denial of service.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · affected: Red Hat OpenShift Container Platform 4 · no fix planned: Red Hat OpenShift Container Platform 4 · updated 2026-09-15 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89552.json)\n\n**kernel: Linux kernel: Denial of Service via NULL pointer dereference in parameter handling** — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-15.\n\nAffected:\n\n- Red Hat OpenShift Container Platform 4\n\nNo fix planned:\n\n- Red Hat OpenShift Container Platform 4\n\n## Remediation\n\nFix deferred","depth":"sunlit","depthScore":23,"depthScoreParts":{"impact":22.5,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":204051,"id":"CVE-2026-89552","ts":1789490231205,"field":"cvss","old":null,"new":"4.1"},{"seq":204050,"id":"CVE-2026-89552","ts":1789490231205,"field":"severity","old":"none","new":"medium"},{"seq":147478,"id":"CVE-2026-89552","ts":1789270211066,"field":"cvss","old":null,"new":"4.1"},{"seq":147477,"id":"CVE-2026-89552","ts":1789270211066,"field":"severity","old":"none","new":"medium"},{"seq":109238,"id":"CVE-2026-89552","ts":1789183731098,"field":"cvss","old":null,"new":"4.1"},{"seq":109237,"id":"CVE-2026-89552","ts":1789183731098,"field":"severity","old":"none","new":"medium"}]}