CVE-2026-89511Medium· 5.5▾ SunlitA flaw was found in the qede driver in the Linux kernel. Under specific memory pressure conditions, the driver can encounter a NULL pointer dereference when processing network traffic using TPA (TCP Segmentation Offload) continuation fragm…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 30.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.2%
— → 5.9
none → medium
— → 5.9
none → medium
— → 7.5
none → high
7.5 → 5.9
high → medium
5.9 → 7.5
medium → high
0.2% → 0.7%
Last analysed / modified upstream
7.5 → 5.5
high → medium
A flaw was found in the qede driver in the Linux kernel. Under specific memory pressure conditions, the driver can encounter a NULL pointer dereference when processing network traffic using TPA (TCP Segmentation Offload) continuation fragments. This issue stems from an uninitialized data pointer, which can lead to the system attempting to use an invalid memory page. Consequently, this can trigger a kernel panic, causing a Denial of Service (DoS) for the affected system.
kernel: qede: Fix NULL pointer dereference in TPA fragment processing — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-18.
Affected:
No fix planned:
Not affected:
Fix deferred
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-89686High· 7.0kernel: nfsd: fix BUG_ON in nfsd4_alloc_layout_stateid on racing delegation revoke (CVE-2026-89686)
CVE-2026-89709High· 7.0kernel: lockd, nfsd: RCU-protect nlmsvc_ops dispatch (CVE-2026-89709)
CVE-2026-89442Medium· 5.5kernel: platform/x86: ISST: Validate socket ID in clos_assoc ioctl (CVE-2026-89442)
CVE-2026-89696Medium· 5.5kernel: nfsd: block non-SAVEFH ops after FOREIGN PUTFH to prevent NULL deref (CVE-2026-89696)
CVE-2026-80963Medium· 5.5kernel: dm-stats: fix a crash if allocation of per-cpu data fails (CVE-2026-80963)
CVE-2026-80984Medium· 5.5kernel: net/smc: do not dereference an unset send buffer on the SMC-D teardown path (CVE-2026-80984)