---
id: CVE-2026-89552
title: >-
  kernel: Linux kernel: Denial of Service via NULL pointer dereference in
  parameter handling (CVE-2026-89552)
summary: >-
  A flaw was found in the Linux kernel. When updating charp parameters, an
  allocation failure can cause the parameter to be set to NULL before the new
  value is successfully allocated. This can lead to a kernel NULL pointer
  dereference, which…
severity: medium
cvss: 4.1
cvssVector: 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H'
cvssSource: vendor
cwe: CWE-476
vendor: Red Hat
product: Red Hat OpenShift Container Platform 4
affected:
  - openshift_container_platform 4
published: '2026-09-11'
updated: '2026-09-15'
sourceUpdated: '2026-09-15T04:57:48+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89552.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89552.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-89552'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2532253'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-89552'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-89552'
  - url: 'https://git.kernel.org/stable/c/0d8e2404925a0607ffec79a53170715a46936896'
  - url: 'https://git.kernel.org/stable/c/3dfaae04243cde460d82dfc2a7dd0bb6664d20ae'
  - url: 'https://git.kernel.org/stable/c/614f873268c5b172804c9af6639bd17b7e1e2359'
  - url: 'https://git.kernel.org/stable/c/704ecd010d4a9b33160e40b74eb402f6b86a18e0'
tags:
  - csaf
  - vex
  - red-hat
  - cve.org
epss: 0.00168
epssPercentile: 0.06464
ingestedAt: '2026-09-14T11:11:19.886Z'
---

## Overview

A flaw was found in the Linux kernel. When updating charp parameters, an allocation failure can cause the parameter to be set to NULL before the new value is successfully allocated. This can lead to a kernel NULL pointer dereference, which may result in a system crash and a denial of service.

## Vendor advisories

- **Red Hat VEX** · Moderate · affected: Red Hat OpenShift Container Platform 4 · no fix planned: Red Hat OpenShift Container Platform 4 · updated 2026-09-15 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89552.json)

**kernel: Linux kernel: Denial of Service via NULL pointer dereference in parameter handling** — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-15.

Affected:

- Red Hat OpenShift Container Platform 4

No fix planned:

- Red Hat OpenShift Container Platform 4

## Remediation

Fix deferred
