PatchSiren cyber security CVE debrief
CVE-2026-89971 Linux CVE debrief
A vulnerability in the Linux kernel's NVMe subsystem can lead to an invalid zoned configuration, causing a shift-out-of-bounds error when I/O is submitted to a zoned queue with a zero zone size. The issue arises from a faulty check in nvme_update_ns_info_block(), which fails to properly handle positive NVMe status codes returned by nvme_query_zone_info(). This results in the zoned limits being updated with a zero zone size, leading to potential I/O errors or UBSAN warnings. Linux kernel developers and administrators should assess exposure and apply the patch to prevent potential issues.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-16
- Original CVE updated
- 2026-10-03
- Advisory published
- 2026-09-16
- Advisory updated
- 2026-10-03
Who should care
Linux kernel developers and administrators responsible for NVMe subsystem configuration and maintenance should assess exposure and apply the patch to prevent potential issues. They should also verify the NVMe subsystem configuration to prevent invalid zoned setups and monitor for potential I/O errors or UBSAN warnings related to zoned queues.
Why it matters
The vulnerability can lead to an invalid zoned configuration, causing potential I/O errors or UBSAN warnings. Linux kernel developers and administrators should assess exposure and apply the patch to prevent potential issues.
- Potential I/O errors or UBSAN warnings related to zoned queues
- Invalid zoned configuration can cause issues with disk_zone_no() and blk_zone_wplug_handle_write()
Technical summary
The Linux kernel's NVMe subsystem has a vulnerability that can lead to an invalid zoned configuration. When nvme_query_zone_info() returns a positive NVMe status code, nvme_update_ns_info_block() does not properly handle it, causing the zoned limits to be updated with a zero zone size. This can lead to a shift-out-of-bounds error when I/O is submitted to a zoned queue. The issue can be addressed by updating the zoned limits correctly and verifying the NVMe subsystem configuration to prevent invalid zoned setups. Affected Linux kernel developers and administrators should assess exposure and apply the patch to prevent potential issues.
Defensive priority
Medium
Recommended defensive actions
- Review and apply the kernel patch to update the zoned limits correctly
- Verify the NVMe subsystem configuration to prevent invalid zoned setups
- Monitor for potential I/O errors or UBSAN warnings related to zoned queues
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
Evidence notes
The vulnerability was introduced due to a faulty check in nvme_update_ns_info_block(), which did not properly handle positive NVMe status codes returned by nvme_query_zone_info(). The check failed to account for the possibility of a positive NVMe status code, leading to the zoned limits being updated with a zero zone size. This issue can be addressed by updating the zoned limits correctly and verifying the NVMe subsystem configuration to prevent invalid zoned setups.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-89971 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-89971
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-89971 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-89971
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/3838e80fcfb32e62baffb63c6dc0a60153665a4d
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/7fad53ae2052a2b4fc7ca567d6555bdb1176ba35
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/a75258e651d91ec25424cd94d824d192c11ccc24
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/bb6dafa79040357cf5043836e1db108c2af8b1e1
416baaa9-dc9f-4396-8d5f-8c081fb06d67
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.