CVE-2026-89481
CVE CVE-2026-89481EUVD EUVD-2026-76387Published 2026-09-11T19:43:36.000ZLast changed 2026-09-14T12:00:18.000ZCVSS 7.5
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: fix host memory disclosure on R2T for a read command nvme_tcp_handle_r2t() does not check the direction of the request the R2T refers to. A malicious controller can send an R2T for a READ and the host will answer it: nvme_tcp_setup_h2c_data_pdu() builds the H2CData header and nvme_tcp_try_send_data() sends the request's data buffer. That buffer is the READ destination, so its contents go to the controller. The command then completes normally and nothing is logged. Against a test controller that answers every READ with an R2T, a 4096 byte buffered read returned all 4096 bytes, split over two R2Ts. The pages contained stale kernel data, including an array of struct page pointers. Reject an R2T for a request that is not a write.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux patch: 6.1.188; patch: 0; patch: 6.6.157; 3f2304f8c6d6ed97849057bd16fee99e434ca796 <bc4013c7cce58d46f792c8c87bc8c8318a70190e; 3f2304f8c6d6ed97849057bd16fee99e434ca796 <6efbc52237facda35d2d874fe1765bb4839275d8; patch: 6.18.50; 3f2304f8c6d6ed97849057bd16fee99e434ca796 <a4c3c7310156493797c920b10d8648c07aa05403; 3f2304f8c6d6ed97849057bd16fee99e434ca796 <3a0b05145053a5fad1a2ddb4e4d87b07385e63e5; 5.0; patch: 7.3-rc1; patch: 6.12.109; 3f2304f8c6d6ed97849057bd16fee99e434ca796 <3b3d27670c0c890ba7cf1bc3614cab61bde6d25c; patch: 7.2.4; 3f2304f8c6d6ed97849057bd16fee99e434ca796 <49a4dcf57608ebf6432dbcb203ed25e7ed581445
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.