Affects the Linux kernel (widely deployed). Kernel memory corruption can compromise many systems and services; broad org-wide impact likely.
CVE-2026-89536
Linux kernel SUNRPC TLS handshake race -> use-after-free and kernel compromise
Is CVE-2026-89536 being exploited?
Not confirmed. CVE-2026-89536 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.63% probability of exploitation in the next 30 days.
How severe is CVE-2026-89536?
CVE-2026-89536 is rated Critical with a CVSS score of 9.8. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-89536?
Yes. A fix has been recorded for CVE-2026-89536. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-89536 affect?
CVE-2026-89536 affects Linux kernel (SUNRPC/TLS client), NFS/SUNRPC clients on Linux, Major Linux distributions (kernel packages). Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-89536?
Apply vendor kernel updates (upstream stable commits) and reboot ASAP.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Remote-triggerable kernel memory corruption via SUNRPC TLS handshake race, causing crashes, privilege escalation or potential remote code execution.
Immediate action required
- affected>= 75eb6af7acdf566c68d61e98e67ee2f235201c02 and < 15431820f448e09f8029b670d5c82aa5917d4625
- affected>= 75eb6af7acdf566c68d61e98e67ee2f235201c02 and < 1de391e8b94e31b45c19c16dbf315e294810c7de
- affected>= 75eb6af7acdf566c68d61e98e67ee2f235201c02 and < 7fbb6d2ab0391eb8d1f1a68e6bc263ef02cea61b
- affected>= 75eb6af7acdf566c68d61e98e67ee2f235201c02 and < a89dd597458848b463d284b15e42a8078beeb046
- affected6.5
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.