PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-89329 Red Hat CVE debrief

A local attacker with access to the multipathd UNIX control socket can exploit this vulnerability by sending valid commands and then ceasing to read replies, causing the multipathd listener thread to block and leading to a Denial of Service (DoS) where legitimate Inter-Process Communication (IPC) operations may hang or time out. The vulnerability affects multipathd installations and requires verification and patching prioritization to prevent potential DoS attacks. System administrators and security teams should assess their exposure and prioritize patching or verifying their systems.

Vendor
Red Hat
Product
Red Hat Enterprise Linux 10
CVSS
MEDIUM 6.2
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-11
Original CVE updated
2026-09-11
Advisory published
2026-09-11
Advisory updated
2026-09-11

Who should care

System administrators and security teams responsible for managing multipathd installations should assess their exposure and prioritize patching or verifying their systems. Defenders should care about CVE-2026-89329 because it can lead to a Denial of Service (DoS) in multipathd installations, potentially impacting system availability and requiring verification and patching prioritization.

Why it matters

Defenders should care about CVE-2026-89329 because it can lead to a Denial of Service (DoS) in multipathd installations, potentially impacting system availability and requiring verification and patching prioritization.

  • Potential Denial of Service (DoS) impacting legitimate Inter-Process Communication (IPC) operations
  • Verification of multipathd installations and patching prioritization required

Technical summary

The multipathd UNIX control socket is vulnerable to a Denial of Service (DoS) attack, where a local attacker can send valid commands and then cease to read replies, causing the multipathd listener thread to block. This vulnerability affects multipathd installations and has a CVSS score of 6.2 with a medium severity level. Defenders should prioritize verifying and patching multipathd installations to prevent potential DoS attacks. The vulnerability does not result in privilege escalation, arbitrary code execution, or impact data confidentiality or integrity.

Defensive priority

Defenders should prioritize verifying and patching multipathd installations to prevent potential DoS attacks.

Recommended defensive actions

  • Verify multipathd installations and apply patches or updates as available
  • Monitor multipathd logs for unusual activity
  • Implement additional security controls to prevent local attackers from accessing the multipathd UNIX control socket
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, but additional information on affected versions and remediation steps is limited. Defenders should verify multipathd installations and apply patches or updates as available. The vulnerability has a CVSS score of 6.2 and a medium severity level. Additional information can be found in the official CVE Program record and NIST NVD detail page.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-89329 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-89329

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-89329 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-89329

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.