CVE-2026-89511
Linux · Kernel
A NULL pointer dereference vulnerability in the Linux kernel qede driver allows unauthenticated attackers to cause a kernel panic via memory-exhausting TPA fragment processing.
Executive summary
A critical vulnerability exists in the Linux kernel qede driver that can be exploited to trigger a system-wide denial of service via a kernel panic.
Vulnerability
The vulnerability is a NULL pointer dereference within the qede network driver, specifically occurring during TPA fragment processing. An unauthenticated attacker can trigger this flaw under memory pressure conditions, leading to a kernel panic and subsequent system crash.
Business impact
The primary impact of this vulnerability is a high-severity denial of service. Because the flaw resides in the kernel, a successful exploit will crash the entire operating system, resulting in unplanned downtime for critical infrastructure or services hosted on the affected hardware. With a CVSS score of 7.5, this vulnerability represents a significant risk to availability and business continuity.
Remediation
Immediate Action: Update the Linux kernel to versions 6.12.109, 6.18.50, 7.2.4, or later to incorporate the required memory management fix.
Proactive Monitoring: Monitor system logs for kernel panic events and recurring driver-specific errors related to the qede interface.
Compensating Controls: Implement network-level rate limiting or traffic shaping to reduce the likelihood of the memory pressure conditions required to trigger the flaw.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the potential for a complete system crash, this vulnerability should be prioritized for remediation in any environment utilizing the qede driver. Security teams should coordinate with system administrators to apply the patched kernel versions during the next available maintenance window to ensure service stability and prevent potential denial of service attacks.
More Linux CVEs all →
History
CVE Brief tracked this CVE 1 day before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 7.5 (3.1)
- Analyst report written