Kernel remote code execution in the Linux SMB client affects widely deployed Linux distributions and can lead to full host compromise; high-impact, broadly used software.
CVE-2026-89633
Linux kernel SMB client OOB read/write enables remote code execution
Is CVE-2026-89633 being exploited?
Not confirmed. CVE-2026-89633 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.48% probability of exploitation in the next 30 days.
How severe is CVE-2026-89633?
CVE-2026-89633 is rated Critical with a CVSS score of 9.8. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-89633?
Yes. A fix has been recorded for CVE-2026-89633. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-89633 affect?
CVE-2026-89633 affects Linux kernel (SMB client coalesce_t2), Linux distributions with vulnerable kernels, Systems mounting SMB/CIFS shares. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-89633?
Update to patched kernel ASAP; block untrusted SMB servers until patched
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
A remote SMB server can trigger out‑of‑bounds reads/writes via DataOffset, enabling crashes or kernel-level RCE when a client connects.
Immediate action required
- affected>= e4eb295d38b57f4d4b956942a48887eb252d97c6 and < 672cf86aa6aa0fb4012ce4c3b3498df42ad67a4e
- affected>= e4eb295d38b57f4d4b956942a48887eb252d97c6 and < 033bc80019f07d158630df4e69b19a49010f54f1
- affected>= e4eb295d38b57f4d4b956942a48887eb252d97c6 and < 6343c1da561962688f203362d80d6a3bfa39fa1b
- affected2.6.12
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.