---
id: CVE-2026-89596
title: >-
  kernel: forcedeth: fix off-by-one when saving/restoring non-PCI config space
  (CVE-2026-89596)
summary: >-
  A flaw was found in the Linux kernel's forcedeth driver. An off-by-one error
  in the `nv_suspend()` and `nv_resume()` functions, which handle saving and
  restoring non-PCI configuration space, can lead to an out-of-bounds memory
  access. This…
severity: medium
cvss: 5.5
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'
cvssSource: vendor
cwe: CWE-125
vendor: Red Hat
product: Linux
affected:
  - >-
    Linux >= 1a1ca86158eee303af5270338695f90bc7ae02b3 <
    effd589568b2c4399894a23000286210c60af6d7
  - >-
    Linux >= 1a1ca86158eee303af5270338695f90bc7ae02b3 <
    702aa4a44c87026b97b1da5c5ca80e1fa8a9875a
  - >-
    Linux >= 1a1ca86158eee303af5270338695f90bc7ae02b3 <
    fc71c6c3d3e3bb17474dcd1162aea6783a452a64
  - >-
    Linux >= 1a1ca86158eee303af5270338695f90bc7ae02b3 <
    c4d5953582463f45e48b14ef9815e5fb636f7e1f
  - >-
    Linux >= 1a1ca86158eee303af5270338695f90bc7ae02b3 <
    9379f8527ca60d92715c90b32f1b477de9ec32cb
  - >-
    Linux >= 1a1ca86158eee303af5270338695f90bc7ae02b3 <
    0c3f4544ff3873594c8af1b907b4ac4e6d5ce005
  - >-
    Linux >= 1a1ca86158eee303af5270338695f90bc7ae02b3 <
    c4f196bfeedd71e56aba4b63bd8f919edb2f7056
  - >-
    Linux >= 1a1ca86158eee303af5270338695f90bc7ae02b3 <
    9393f1d656a79693e0c123ff7bc7c5c0f708046d
  - Linux 2.6.27
published: '2026-09-11'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T18:32:05+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89596.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89596.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-89596'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2532083'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-89596'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-89596'
  - url: >-
      https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-89596.mbox
  - url: 'https://git.kernel.org/stable/c/effd589568b2c4399894a23000286210c60af6d7'
  - url: 'https://git.kernel.org/stable/c/702aa4a44c87026b97b1da5c5ca80e1fa8a9875a'
  - url: 'https://git.kernel.org/stable/c/fc71c6c3d3e3bb17474dcd1162aea6783a452a64'
  - url: 'https://git.kernel.org/stable/c/c4d5953582463f45e48b14ef9815e5fb636f7e1f'
  - url: 'https://git.kernel.org/stable/c/9379f8527ca60d92715c90b32f1b477de9ec32cb'
  - url: 'https://git.kernel.org/stable/c/0c3f4544ff3873594c8af1b907b4ac4e6d5ce005'
  - url: 'https://git.kernel.org/stable/c/c4f196bfeedd71e56aba4b63bd8f919edb2f7056'
  - url: 'https://git.kernel.org/stable/c/9393f1d656a79693e0c123ff7bc7c5c0f708046d'
tags:
  - csaf
  - vex
  - red-hat
  - cve.org
epss: 0.00173
epssPercentile: 0.07016
scores:
  vendor: 5.5
  cna: 7.1
ingestedAt: '2026-09-14T15:23:07.451Z'
---

## Overview

A flaw was found in the Linux kernel's forcedeth driver. An off-by-one error in the `nv_suspend()` and `nv_resume()` functions, which handle saving and restoring non-PCI configuration space, can lead to an out-of-bounds memory access. This occurs during system suspend and resume operations. If specific kernel debugging options are enabled, this vulnerability could cause the kernel to crash, leading to a denial of service.

## Vendor advisories

- **Red Hat VEX** · Moderate · updated 2026-09-18 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89596.json)

**kernel: forcedeth: fix off-by-one when saving/restoring non-PCI config space** — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-18.

Not affected:

- Red Hat Enterprise Linux 10
- Red Hat Enterprise Linux 6
- Red Hat Enterprise Linux 7
- Red Hat Enterprise Linux 8
- Red Hat Enterprise Linux 9
- Red Hat OpenShift Container Platform 4

## Remediation

Refer to the advisory for fix availability.
