Linux kernel vulnerability affects a widely deployed OS kernel and RDMA/NFS stacks used in servers/cloud — high-impact, organization-wide risk.
CVE-2026-89526
Linux svcrdma parsing flaw allows remote kernel memory disclosure
Is CVE-2026-89526 being exploited?
Not confirmed. CVE-2026-89526 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.63% probability of exploitation in the next 30 days.
How severe is CVE-2026-89526?
CVE-2026-89526 is rated Critical with a CVSS score of 9.8. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-89526?
Yes. A fix has been recorded for CVE-2026-89526. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-89526 affect?
CVE-2026-89526 affects Linux kernel (svcrdma), RDMA-enabled NFS/RPC servers, Cloud and on-prem Linux servers using RDMA. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-89526?
Apply patched kernel immediately; block/unexpose RDMA until updated; reboot if required.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Remote attacker can craft RPC/RDMA Read chunks to read/overflow buffers, causing kernel memory disclosure, possible memory corruption and service crashes.
Immediate action required
- affected>= d96962e6d0e281bab6a48e83b42f5dce6eb28bf4 and < 5ab3f6d882fe07ae5e61d0bcfeea00b9409155c2
- affected>= d96962e6d0e281bab6a48e83b42f5dce6eb28bf4 and < f84ec84d8d4bc65f9ae23372570349687f66fa39
- affected>= d96962e6d0e281bab6a48e83b42f5dce6eb28bf4 and < 577097455d084610fc31e91e6a61c5793b6f04ba
- affected>= d96962e6d0e281bab6a48e83b42f5dce6eb28bf4 and < 3779b7b9e7d1c8ba4738f9d327de3b0288cefe9b
- affected5.11
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.