---
id: CVE-2026-89511
title: >-
  kernel: qede: Fix NULL pointer dereference in TPA fragment processing
  (CVE-2026-89511)
summary: >-
  A flaw was found in the qede driver in the Linux kernel. Under specific memory
  pressure conditions, the driver can encounter a NULL pointer dereference when
  processing network traffic using TPA (TCP Segmentation Offload) continuation
  fragm…
severity: medium
cvss: 5.5
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'
cvssSource: vendor
cwe: CWE-476
vendor: Red Hat
product: Red Hat Enterprise Linux 9
affected:
  - enterprise_linux 10
  - enterprise_linux 7
  - enterprise_linux 8
  - enterprise_linux 9
  - openshift_container_platform 4
published: '2026-09-11'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T12:49:08+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89511.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89511.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-89511'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2532100'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-89511'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-89511'
  - url: >-
      https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-89511.mbox
  - url: 'https://git.kernel.org/stable/c/e2214e2793154b745436e46c6a9a7985d9b3781d'
  - url: 'https://git.kernel.org/stable/c/dd8bc0a9d87d2b048711edd17ba7286432edd285'
  - url: 'https://git.kernel.org/stable/c/fa7c9bd2c4a8de167e2fb32968ca4d91dd774375'
  - url: 'https://git.kernel.org/stable/c/a5e1fdc126ab337d601d1a00cc4b47910679d005'
  - url: 'https://git.kernel.org/stable/c/7f911e208b3ca2c76d9f2bbba1f54b9403568c10'
  - url: 'https://git.kernel.org/stable/c/2a952fb1b20d83e83ca852773e6188511f7d2191'
  - url: 'https://git.kernel.org/stable/c/f5c8619ccbd70102642120c4c6fda1c048a555fd'
  - url: 'https://git.kernel.org/stable/c/06aa3d26327f24edd039ff249672fdf6f2ba5695'
tags:
  - csaf
  - vex
  - red-hat
  - cve.org
  - score-dispute
epss: 0.00716
epssPercentile: 0.51779
scores:
  vendor: 5.5
  cna: 7.5
ingestedAt: '2026-09-14T15:23:07.452Z'
---

## Overview

A flaw was found in the qede driver in the Linux kernel. Under specific memory pressure conditions, the driver can encounter a NULL pointer dereference when processing network traffic using TPA (TCP Segmentation Offload) continuation fragments. This issue stems from an uninitialized data pointer, which can lead to the system attempting to use an invalid memory page. Consequently, this can trigger a kernel panic, causing a Denial of Service (DoS) for the affected system.

## Vendor advisories

- **Red Hat VEX** · Moderate · affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4 · no fix planned: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, … · updated 2026-09-18 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89511.json)

**kernel: qede: Fix NULL pointer dereference in TPA fragment processing** — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-18.

Affected:

- Red Hat Enterprise Linux 10
- Red Hat Enterprise Linux 7
- Red Hat Enterprise Linux 8
- Red Hat Enterprise Linux 9
- Red Hat OpenShift Container Platform 4

No fix planned:

- Red Hat Enterprise Linux 10
- Red Hat Enterprise Linux 7
- Red Hat Enterprise Linux 8
- Red Hat Enterprise Linux 9
- Red Hat OpenShift Container Platform 4

Not affected:

- Red Hat Enterprise Linux 6

## Remediation

Fix deferred
