Linux kernel exploitability at scale; SUNRPC is widely deployed and can lead to RCE/data exposure across infrastructure.
CVE-2026-89551
Linux kernel SUNRPC xdr_buf_trim underflow enables downstream OOB/memory corruption.
Is CVE-2026-89551 being exploited?
Not confirmed. CVE-2026-89551 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.52% probability of exploitation in the next 30 days.
How severe is CVE-2026-89551?
CVE-2026-89551 is rated Critical with a CVSS score of 9.8. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-89551?
Yes. A fix has been recorded for CVE-2026-89551. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-89551 affect?
CVE-2026-89551 affects Linux kernel (SUNRPC/xdr_buf), Systems using gss_krb5_unwrap_v2 (RPC/GSS Kerberos). Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-89551?
Apply latest Linux kernel stable updates or backport the commit; restart RPC/GSS services.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Unsigned underflow makes buf->len wrap, causing downstream out-of-bounds access and memory corruption; may enable remote code execution or data disclosure via RPC/GSS.
Immediate action required
- affected>= 4c190e2f913f038c9c91ee63b59cd037260ba353 and < e6267cccd7b05cc514e57f2160aa8db85f5c2701
- affected>= 4c190e2f913f038c9c91ee63b59cd037260ba353 and < ad0cce80d4af2f74674e8b635d97aa3880e83da8
- affected>= 4c190e2f913f038c9c91ee63b59cd037260ba353 and < 85e9602650e9df07190abe817cee3b4d9bc3df17
- affected>= 4c190e2f913f038c9c91ee63b59cd037260ba353 and < 3f491306dcb673ff5e78e1044ba450c58978774e
- affected3.9
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.