PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-89971 Linux CVE debrief

A vulnerability in the Linux kernel's NVMe subsystem can lead to an invalid zoned configuration, causing a shift-out-of-bounds error when I/O is submitted to a zoned queue with a zero zone size. The issue arises from a faulty check in nvme_update_ns_info_block(), which fails to properly handle positive NVMe status codes returned by nvme_query_zone_info(). This results in the zoned limits being updated with a zero zone size, leading to potential I/O errors or UBSAN warnings. Linux kernel developers and administrators should assess exposure and apply the patch to prevent potential issues.

Vendor
Linux
Product
Unknown
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-16
Original CVE updated
2026-10-03
Advisory published
2026-09-16
Advisory updated
2026-10-03

Who should care

Linux kernel developers and administrators responsible for NVMe subsystem configuration and maintenance should assess exposure and apply the patch to prevent potential issues. They should also verify the NVMe subsystem configuration to prevent invalid zoned setups and monitor for potential I/O errors or UBSAN warnings related to zoned queues.

Why it matters

The vulnerability can lead to an invalid zoned configuration, causing potential I/O errors or UBSAN warnings. Linux kernel developers and administrators should assess exposure and apply the patch to prevent potential issues.

  • Potential I/O errors or UBSAN warnings related to zoned queues
  • Invalid zoned configuration can cause issues with disk_zone_no() and blk_zone_wplug_handle_write()

Technical summary

The Linux kernel's NVMe subsystem has a vulnerability that can lead to an invalid zoned configuration. When nvme_query_zone_info() returns a positive NVMe status code, nvme_update_ns_info_block() does not properly handle it, causing the zoned limits to be updated with a zero zone size. This can lead to a shift-out-of-bounds error when I/O is submitted to a zoned queue. The issue can be addressed by updating the zoned limits correctly and verifying the NVMe subsystem configuration to prevent invalid zoned setups. Affected Linux kernel developers and administrators should assess exposure and apply the patch to prevent potential issues.

Defensive priority

Medium

Recommended defensive actions

  • Review and apply the kernel patch to update the zoned limits correctly
  • Verify the NVMe subsystem configuration to prevent invalid zoned setups
  • Monitor for potential I/O errors or UBSAN warnings related to zoned queues
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.

Evidence notes

The vulnerability was introduced due to a faulty check in nvme_update_ns_info_block(), which did not properly handle positive NVMe status codes returned by nvme_query_zone_info(). The check failed to account for the possibility of a positive NVMe status code, leading to the zoned limits being updated with a zero zone size. This issue can be addressed by updating the zoned limits correctly and verifying the NVMe subsystem configuration to prevent invalid zoned setups.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-89971 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-89971

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-89971 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-89971

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/3838e80fcfb32e62baffb63c6dc0a60153665a4d

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/7fad53ae2052a2b4fc7ca567d6555bdb1176ba35

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/a75258e651d91ec25424cd94d824d192c11ccc24

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/bb6dafa79040357cf5043836e1db108c2af8b1e1

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.