---
id: CVE-2026-89482
title: >-
  kernel: nvme-tcp: do not accept C2HData based on blk_rq_payload_bytes() alone
  (CVE-2026-89482)
summary: >-
  A flaw was found in the nvme-tcp module of the Linux kernel. This
  vulnerability arises from improper handling of C2HData for REQ_OP_WRITE_ZEROES
  commands, where the system fails to adequately validate the data length. A
  remote attacker cou…
severity: high
cvss: 7
cvssVector: 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'
cvssSource: vendor
cwe: CWE-787
vendor: Red Hat
product: Red Hat Enterprise Linux 9
affected:
  - enterprise_linux 10
  - enterprise_linux 8
  - enterprise_linux 9
  - openshift_container_platform 4
published: '2026-09-11'
updated: '2026-09-15'
sourceUpdated: '2026-09-15T17:58:49+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89482.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89482.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-89482'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2532128'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-89482'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-89482'
  - url: >-
      https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-89482.mbox
  - url: 'https://git.kernel.org/stable/c/32ea8ce96b9bd797c59c351ce490ffd97adaa8c0'
  - url: 'https://git.kernel.org/stable/c/dd8906bb8f8d5bf1c9f861e1382c82b87bfe7cab'
  - url: 'https://git.kernel.org/stable/c/7ed0b61bbc145988be292c4d3ec580aebd8d2bcd'
  - url: 'https://git.kernel.org/stable/c/b96e1ff75e5c0ad6e077ac002b1d30b0a2b49528'
  - url: 'https://git.kernel.org/stable/c/b36161701cb366f416afdcf70771d432a7c74753'
  - url: 'https://git.kernel.org/stable/c/6a01b58263108eaf9869bb6f82f07709240c6589'
  - url: 'https://git.kernel.org/stable/c/641ad3a30ba560f0a9a610376c568d7b75d2a2aa'
  - url: 'https://git.kernel.org/stable/c/3a4aa9e6ad3e35f8e24d5eaf38ee4d437075fb36'
tags:
  - csaf
  - vex
  - red-hat
  - cve.org
  - score-dispute
epss: 0.00704
epssPercentile: 0.51873
scores:
  vendor: 7
  cna: 9.8
ingestedAt: '2026-09-14T15:23:07.453Z'
---

## Overview

A flaw was found in the nvme-tcp module of the Linux kernel. This vulnerability arises from improper handling of C2HData for REQ_OP_WRITE_ZEROES commands, where the system fails to adequately validate the data length. A remote attacker could exploit this by sending specially crafted C2HData, leading to a wild-memory-access. This memory corruption can cause a kernel crash, resulting in a Denial of Service (DoS) for the affected system.

## Vendor advisories

- **Red Hat VEX** · Moderate · affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4 · no fix planned: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4 · updated 2026-09-15 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89482.json)

**kernel: nvme-tcp: do not accept C2HData based on blk_rq_payload_bytes() alone** — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-15.

Affected:

- Red Hat Enterprise Linux 10
- Red Hat Enterprise Linux 8
- Red Hat Enterprise Linux 9
- Red Hat OpenShift Container Platform 4

No fix planned:

- Red Hat Enterprise Linux 10
- Red Hat Enterprise Linux 8
- Red Hat Enterprise Linux 9
- Red Hat OpenShift Container Platform 4

Not affected:

- Red Hat Enterprise Linux 6
- Red Hat Enterprise Linux 7

## Remediation

Affected
