PT-2026-51883 · Linux+2 · Linux Kernel+2

·

CVE-2026-52989

·

Published

2026-04-08

·

Updated

2026-09-07

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A flaw in the nvmet-tcp component occurs because the nvmet tcp build pdu iovec() function does not propagate errors to its callers when detecting out-of-bounds PDU (Protocol Data Unit) lengths or offsets. Because the function returns void, callers like nvmet tcp handle h2c data pdu() remain unaware of fatal errors, leaving the cmd->recv msg.msg iter uninitialized. This can result in the socket receiving loop attempting to read incoming network data into the uninitialized iterator, potentially leading to memory corruption, denial of service, or arbitrary code execution.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Initialization

Use of Uninitialized Resource

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-13939
CVE-2026-52989
ECHO-D5F4-75AC-53F9
OESA-2026-3317
OPENSUSE-SU-2026:21555-1
SUSE-SU-2026:23066-1
SUSE-SU-2026:23068-1
SUSE-SU-2026:23193-1
SUSE-SU-2026:23194-1
SUSE-SU-2026:23221-1
SUSE-SU-2026:23231-1
SUSE-SU-2026:23237-1
SUSE-SU-2026:23241-1
SUSE-SU-2026:23244-1
SUSE-SU-2026:3130-1
SUSE-SU-2026:3166-1
USN-8566-1
USN-8567-1
USN-8568-1
USN-8569-1
USN-8574-1
USN-8574-2
USN-8574-3
USN-8593-1
USN-8595-1
USN-8595-2
USN-8595-3
USN-8596-1
USN-8603-1
USN-8606-1
USN-8607-1
USN-8608-1
USN-8609-1
USN-8618-1
USN-8619-1
USN-8631-1
USN-8631-2
USN-8631-3
USN-8631-4
USN-8636-1
USN-8636-2
USN-8661-1
USN-8661-2
USN-8661-3
USN-8661-4
USN-8663-1
USN-8664-1
USN-8665-1
USN-8666-1
USN-8666-2
USN-8666-3
USN-8667-1
USN-8669-1
USN-8715-1
USN-8728-1

Affected Products

Linuxmint
Linux Kernel
Ubuntu