Remote kernel memory-corruption in the Linux nvme-tcp driver affects many Linux servers using NVMe-over-TCP; can crash or lead to kernel compromise, high disruption for infrastructure.
CVE-2026-89482
Linux nvme-tcp: crafted C2HData leads to kernel memory corruption/crash
Is CVE-2026-89482 being exploited?
Not confirmed. CVE-2026-89482 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.70% probability of exploitation in the next 30 days.
How severe is CVE-2026-89482?
CVE-2026-89482 is rated Critical with a CVSS score of 9.8. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-89482?
Yes. A fix has been recorded for CVE-2026-89482. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-89482 affect?
CVE-2026-89482 affects Linux kernel (nvme-tcp), Linux distributions with affected kernels, Servers using NVMe over TCP, Storage hosts/virtualized platforms using nvme-tcp. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-89482?
Apply vendor/distribution kernel updates that include the nvme-tcp fix and reboot affected hosts.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Remote NVMe-over-TCP C2HData can cause kernel memory corruption, crashes, and may enable kernel-level compromise via crafted network traffic.
Immediate action required
- affected>= 25e5cb780e62bde432b401f312bb847edc78b432 and < b36161701cb366f416afdcf70771d432a7c74753
- affected>= 25e5cb780e62bde432b401f312bb847edc78b432 and < 6a01b58263108eaf9869bb6f82f07709240c6589
- affected>= 25e5cb780e62bde432b401f312bb847edc78b432 and < 641ad3a30ba560f0a9a610376c568d7b75d2a2aa
- affected>= 25e5cb780e62bde432b401f312bb847edc78b432 and < 3a4aa9e6ad3e35f8e24d5eaf38ee4d437075fb36
- affectedf507ae6e33cbe56c4e3fe000434fc0ecc263d098
- affectedb1458c16f4e26e87492e58e4d24a1873bd09232a
- affected>= 5.4.36 and < 5.5
- affected>= 5.6.8 and < 5.7
- affected5.7
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.