# CVE-2026-89743

## Summary

- **CVE ID:** CVE-2026-89743
- **Severity:** HIGH
- **CVSS Score:** 7.7 (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H)
- **CWE:** N/A
- **Published:** Sep 11, 2026
- **Last Modified:** Sep 13, 2026

## Description

In the Linux kernel, the following vulnerability has been resolved:

misc: nsm: bound the device-reported response length

nsm_sendrecv_msg_locked() stores the virtqueue used-ring length reported
by the NSM device into msg->resp.len without bounding it to the response
buffer. A malicious or buggy backend can report a length larger than the
response buffer; parse_resp_raw() then copies that many bytes out of the
fixed buffer to user space, disclosing adjacent kernel heap (an
out-of-bounds read). The request path already floors its length in
fill_req_raw(); the response path lacks the symmetric check.

Clamp the stored length to the size of the response buffer. Well-behaved
devices report no more than the posted buffer size, so conforming traffic
is unaffected.

## Affected Products

- Linux — Linux (b9873755a6c8ccfce79094c4dce9efa3ecb1a749)
- Linux — Linux (6.8)
- Linux — Linux (0)
- Linux — Linux (6.12.109)
- Linux — Linux (6.18.50)
- Linux — Linux (7.2.4)
- Linux — Linux (7.3-rc1)

## References

- [CNA](https://git.kernel.org/stable/c/339f19b9a6171289b0e797deb8bda80b9a1fcc30)
- [CNA](https://git.kernel.org/stable/c/29e634a18957acda11383a15ab98a91c4ae9e294)
- [CNA](https://git.kernel.org/stable/c/2aa0fb9c96f894a9c179a48e7522ea6705800adf)
- [CNA](https://git.kernel.org/stable/c/808e530654a5354e6df78863a5d61e4d44e67235)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.14%
- **EPSS Percentile:** 4.0

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-17._