{"id":"CVE-2026-89575","title":"kernel: dm raid1: reserve space for NUL-terminator in build_constructor_string() (CVE-2026-89575)","summary":"A flaw was found in the Linux kernel's device mapper (dm-raid1) component. This vulnerability occurs in the `build_constructor_string()` function, where insufficient space is reserved for a NUL-terminator when formatting a string with `spr…","severity":"high","cvss":7,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","cvssSource":"vendor","cwe":"CWE-170","vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","affected":["enterprise_linux 10","enterprise_linux 6","enterprise_linux 7","enterprise_linux 8","enterprise_linux 9","openshift_container_platform 4"],"published":"2026-09-11","updated":"2026-09-18","sourceUpdated":"2026-09-18T22:07:37+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89575.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89575.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-89575"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2532259"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-89575"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89575"},{"url":"https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-89575.mbox"},{"url":"https://git.kernel.org/stable/c/0a3657ebd6b517b60cdc5123894047616974e25b"},{"url":"https://git.kernel.org/stable/c/644140527ae494cedf3b5c0ecd16287deaea7a66"},{"url":"https://git.kernel.org/stable/c/73c37fe54cd056d07461b142ab0b8b81e1ef6ad8"},{"url":"https://git.kernel.org/stable/c/f79b53ca3a68a46c6fc3b30b148d1dfb1b33ea8b"},{"url":"https://git.kernel.org/stable/c/35ba81c93fe7392c973af9881640180490e76f34"},{"url":"https://git.kernel.org/stable/c/1fcc9f9f35653c5ee1a8b144ec96ff3fc48532f7"},{"url":"https://git.kernel.org/stable/c/7b035983b895db3ae01d9855963d42541db42125"},{"url":"https://git.kernel.org/stable/c/01a0276706c7b6fb758a8e2ff9cf221a3dfcae97"}],"tags":["csaf","vex","red-hat","cve.org"],"epss":0.00227,"epssPercentile":0.1376,"ingestedAt":"2026-09-14T15:23:07.451Z","slug":"CVE-2026-89575","body":"## Overview\n\nA flaw was found in the Linux kernel's device mapper (dm-raid1) component. This vulnerability occurs in the `build_constructor_string()` function, where insufficient space is reserved for a NUL-terminator when formatting a string with `sprintf()`. This oversight can lead to a buffer overflow, potentially allowing an attacker to cause a denial of service or execute arbitrary code.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4 · no fix planned: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, … · updated 2026-09-18 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89575.json)\n\n**kernel: dm raid1: reserve space for NUL-terminator in build_constructor_string()** — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-18.\n\nAffected:\n\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 6\n- Red Hat Enterprise Linux 7\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n\nNo fix planned:\n\n- Red Hat Enterprise Linux 6\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 7\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n\n## Remediation\n\nOut of support scope","depth":"twilight","depthScore":39,"depthScoreParts":{"impact":38.5,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":208095,"id":"CVE-2026-89575","ts":1789922707920,"field":"cvss","old":"4.7","new":"7"},{"seq":208094,"id":"CVE-2026-89575","ts":1789922707920,"field":"severity","old":"medium","new":"high"},{"seq":204031,"id":"CVE-2026-89575","ts":1789490231123,"field":"cvss","old":null,"new":"4.7"},{"seq":204030,"id":"CVE-2026-89575","ts":1789490231123,"field":"severity","old":"none","new":"medium"},{"seq":147482,"id":"CVE-2026-89575","ts":1789270211082,"field":"cvss","old":null,"new":"4.7"},{"seq":147481,"id":"CVE-2026-89575","ts":1789270211082,"field":"severity","old":"none","new":"medium"},{"seq":109230,"id":"CVE-2026-89575","ts":1789183731058,"field":"cvss","old":null,"new":"4.7"},{"seq":109229,"id":"CVE-2026-89575","ts":1789183731058,"field":"severity","old":"none","new":"medium"}]}