{"id":"CVE-2026-89596","title":"kernel: forcedeth: fix off-by-one when saving/restoring non-PCI config space (CVE-2026-89596)","summary":"A flaw was found in the Linux kernel's forcedeth driver. An off-by-one error in the `nv_suspend()` and `nv_resume()` functions, which handle saving and restoring non-PCI configuration space, can lead to an out-of-bounds memory access. This…","severity":"medium","cvss":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","cvssSource":"vendor","cwe":"CWE-125","vendor":"Red Hat","product":"Linux","affected":["Linux >= 1a1ca86158eee303af5270338695f90bc7ae02b3 < effd589568b2c4399894a23000286210c60af6d7","Linux >= 1a1ca86158eee303af5270338695f90bc7ae02b3 < 702aa4a44c87026b97b1da5c5ca80e1fa8a9875a","Linux >= 1a1ca86158eee303af5270338695f90bc7ae02b3 < fc71c6c3d3e3bb17474dcd1162aea6783a452a64","Linux >= 1a1ca86158eee303af5270338695f90bc7ae02b3 < c4d5953582463f45e48b14ef9815e5fb636f7e1f","Linux >= 1a1ca86158eee303af5270338695f90bc7ae02b3 < 9379f8527ca60d92715c90b32f1b477de9ec32cb","Linux >= 1a1ca86158eee303af5270338695f90bc7ae02b3 < 0c3f4544ff3873594c8af1b907b4ac4e6d5ce005","Linux >= 1a1ca86158eee303af5270338695f90bc7ae02b3 < c4f196bfeedd71e56aba4b63bd8f919edb2f7056","Linux >= 1a1ca86158eee303af5270338695f90bc7ae02b3 < 9393f1d656a79693e0c123ff7bc7c5c0f708046d","Linux 2.6.27"],"published":"2026-09-11","updated":"2026-09-18","sourceUpdated":"2026-09-18T18:32:05+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89596.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89596.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-89596"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2532083"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-89596"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89596"},{"url":"https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-89596.mbox"},{"url":"https://git.kernel.org/stable/c/effd589568b2c4399894a23000286210c60af6d7"},{"url":"https://git.kernel.org/stable/c/702aa4a44c87026b97b1da5c5ca80e1fa8a9875a"},{"url":"https://git.kernel.org/stable/c/fc71c6c3d3e3bb17474dcd1162aea6783a452a64"},{"url":"https://git.kernel.org/stable/c/c4d5953582463f45e48b14ef9815e5fb636f7e1f"},{"url":"https://git.kernel.org/stable/c/9379f8527ca60d92715c90b32f1b477de9ec32cb"},{"url":"https://git.kernel.org/stable/c/0c3f4544ff3873594c8af1b907b4ac4e6d5ce005"},{"url":"https://git.kernel.org/stable/c/c4f196bfeedd71e56aba4b63bd8f919edb2f7056"},{"url":"https://git.kernel.org/stable/c/9393f1d656a79693e0c123ff7bc7c5c0f708046d"}],"tags":["csaf","vex","red-hat","cve.org"],"epss":0.00173,"epssPercentile":0.07016,"scores":{"vendor":5.5,"cna":7.1},"ingestedAt":"2026-09-14T15:23:07.451Z","slug":"CVE-2026-89596","body":"## Overview\n\nA flaw was found in the Linux kernel's forcedeth driver. An off-by-one error in the `nv_suspend()` and `nv_resume()` functions, which handle saving and restoring non-PCI configuration space, can lead to an out-of-bounds memory access. This occurs during system suspend and resume operations. If specific kernel debugging options are enabled, this vulnerability could cause the kernel to crash, leading to a denial of service.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · updated 2026-09-18 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89596.json)\n\n**kernel: forcedeth: fix off-by-one when saving/restoring non-PCI config space** — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-18.\n\nNot affected:\n\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 6\n- Red Hat Enterprise Linux 7\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n\n## Remediation\n\nRefer to the advisory for fix availability.","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":30.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":208138,"id":"CVE-2026-89596","ts":1789922723230,"field":"cvss","old":"7.1","new":"5.5"},{"seq":208137,"id":"CVE-2026-89596","ts":1789922723230,"field":"severity","old":"high","new":"medium"},{"seq":197878,"id":"CVE-2026-89596","ts":1789384320782,"field":"cvss","old":"4.7","new":"7.1"},{"seq":197877,"id":"CVE-2026-89596","ts":1789384320782,"field":"severity","old":"medium","new":"high"},{"seq":183735,"id":"CVE-2026-89596","ts":1789356677166,"field":"cvss","old":"7.1","new":"4.7"},{"seq":183734,"id":"CVE-2026-89596","ts":1789356677166,"field":"severity","old":"high","new":"medium"},{"seq":153414,"id":"CVE-2026-89596","ts":1789285350417,"field":"cvss","old":null,"new":"7.1"},{"seq":153413,"id":"CVE-2026-89596","ts":1789285350417,"field":"severity","old":"none","new":"high"},{"seq":147766,"id":"CVE-2026-89596","ts":1789270212207,"field":"cvss","old":null,"new":"4.7"},{"seq":147765,"id":"CVE-2026-89596","ts":1789270212207,"field":"severity","old":"none","new":"medium"},{"seq":109522,"id":"CVE-2026-89596","ts":1789183732270,"field":"cvss","old":null,"new":"4.7"},{"seq":109521,"id":"CVE-2026-89596","ts":1789183732270,"field":"severity","old":"none","new":"medium"}]}