CVE-2026-89743 is a vulnerability in Linux Kernel
Published on September 11, 2026
misc: nsm: bound the device-reported response length
In the Linux kernel, the following vulnerability has been resolved:
misc: nsm: bound the device-reported response length
nsm_sendrecv_msg_locked() stores the virtqueue used-ring length reported
by the NSM device into msg->resp.len without bounding it to the response
buffer. A malicious or buggy backend can report a length larger than the
response buffer; parse_resp_raw() then copies that many bytes out of the
fixed buffer to user space, disclosing adjacent kernel heap (an
out-of-bounds read). The request path already floors its length in
fill_req_raw(); the response path lacks the symmetric check.
Clamp the stored length to the size of the response buffer. Well-behaved
devices report no more than the posted buffer size, so conforming traffic
is unaffected.
Products Associated with CVE-2026-89743
Want to know whenever a new CVE is published for Linux Kernel? stack.watch will email you.
Affected Versions
Linux:- Version b9873755a6c8ccfce79094c4dce9efa3ecb1a749 and below 339f19b9a6171289b0e797deb8bda80b9a1fcc30 is affected.
- Version b9873755a6c8ccfce79094c4dce9efa3ecb1a749 and below 29e634a18957acda11383a15ab98a91c4ae9e294 is affected.
- Version b9873755a6c8ccfce79094c4dce9efa3ecb1a749 and below 2aa0fb9c96f894a9c179a48e7522ea6705800adf is affected.
- Version b9873755a6c8ccfce79094c4dce9efa3ecb1a749 and below 808e530654a5354e6df78863a5d61e4d44e67235 is affected.
- Version 6.8 is affected.
- Before 6.8 is unaffected.
- Version 6.12.109, <= 6.12.* is unaffected.
- Version 6.18.50, <= 6.18.* is unaffected.
- Version 7.2.4, <= 7.2.* is unaffected.
- Version 7.3-rc1, <= * is unaffected.