Description
In the Linux kernel, the following vulnerability has been resolved:

misc: nsm: bound the device-reported response length

nsm_sendrecv_msg_locked() stores the virtqueue used-ring length reported
by the NSM device into msg->resp.len without bounding it to the response
buffer. A malicious or buggy backend can report a length larger than the
response buffer; parse_resp_raw() then copies that many bytes out of the
fixed buffer to user space, disclosing adjacent kernel heap (an
out-of-bounds read). The request path already floors its length in
fill_req_raw(); the response path lacks the symmetric check.

Clamp the stored length to the size of the response buffer. Well-behaved
devices report no more than the posted buffer size, so conforming traffic
is unaffected.
Published: 2026-09-11
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Out-of-bounds read via the Linux NSM driver
Action: Patch
AI Analysis

Impact

In the Linux kernel the NSM (Network Sensor Module) driver fails to bound the response length reported by a backend device. The length is stored in msg->resp.len without checking against the actual buffer size. When parse_resp_raw copies the data to user space, it reads past the end of the kernel buffer, disclosing adjacent kernel heap memory. This flaw allows an attacker with control over a buggy or malicious NSM backend to read arbitrary kernel memory, providing a potential information‑disclosure oracle that could be leveraged for further privileged exploits. It is a classic out‑of‑bounds read weakness (CWE‑125).

Affected Systems

Any Linux system running a kernel that contains the unpatched NSM driver—specifically kernels before commit 29e634a18957acda11383a15ab98a91c4ae9e294. This includes stock kernels and distributions that have not applied the patch, as well as custom kernel builds that incorporate the same logic. The module may remain vulnerable even if not actively loaded, because the flaw exists in the driver code present in the kernel image.

Risk and Exploitability

The vulnerability has a CVSS base score of 7.7, categorizing it as high severity. The EPSS score is below 1 %, indicating that real‑world exploitation is unlikely at present. It is not listed in CISA’s KEV catalog. Exploitation requires the ability to influence a NSM backend device to supply a malformed response length, making the attack vector device‑specific and not a typical remote exploit. The low EPSS suggests that, unless the attacker has physical or privileged access to the device, the risk remains modest, yet the read disclosure can serve as an attack facilitator in higher‑privilege scenarios.

Generated by OpenCVE AI on September 15, 2026 at 19:53 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a kernel update that contains commit 29e634a18957acda11383a15ab98a91c4ae9e294, which clamps the response length to the buffer size.
  • For custom or third‑party NSM backends, ensure that response lengths never exceed the allocated buffer before the driver processes them, or apply a similar check in the backend firmware.
  • Limit connections to the NSM device to trusted, signed backends and disconnect any untrusted or unverified hardware to reduce the attack surface.

Generated by OpenCVE AI on September 15, 2026 at 19:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H'}

cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H'}


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
References
Metrics threat_severity

None

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: misc: nsm: bound the device-reported response length nsm_sendrecv_msg_locked() stores the virtqueue used-ring length reported by the NSM device into msg->resp.len without bounding it to the response buffer. A malicious or buggy backend can report a length larger than the response buffer; parse_resp_raw() then copies that many bytes out of the fixed buffer to user space, disclosing adjacent kernel heap (an out-of-bounds read). The request path already floors its length in fill_req_raw(); the response path lacks the symmetric check. Clamp the stored length to the size of the response buffer. Well-behaved devices report no more than the posted buffer size, so conforming traffic is unaffected.
Title misc: nsm: bound the device-reported response length
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-13T06:33:52.757Z

Reserved: 2026-09-11T19:38:34.761Z

Link: CVE-2026-89743

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:20:04.997

Modified: 2026-09-13T07:17:38.953

Link: CVE-2026-89743

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:46:49Z

Links: CVE-2026-89743 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T20:00:08Z

Weaknesses