Skip to content
Auto-CTI
Back to today
NEW MEDIUM A3

CVE-2026-89575

A NVD · · CVE-2026-89575

Admiralty grading (A–F · 1–6)

Source reliability

  • A Completely reliable
  • B Usually reliable
  • C Fairly reliable
  • D Not usually reliable
  • E Unreliable
  • F Cannot be judged

Information credibility

  • 1 Confirmed
  • 2 Probably true
  • 3 Possibly true
  • 4 Doubtful
  • 5 Improbable
  • 6 Cannot be judged

NATO Admiralty (AJP-2.1) grades confidence, independent of the risk score. Cross-source corroboration isn't tracked for non-CVE news, so single-source items are capped at a lower credibility number; a low number does not imply low quality.

Key metrics

EPSS
0%

Key insight

Pure patch information with no indication of active exploitation or strategic relevance.

Description

The vulnerability CVE-2026-89575 affects the Linux kernel in the Device Mapper RAID1 target. In the function build_constructor_string(), the buffer for the string is not sufficiently sized, so the terminating NUL after up to 20 decimal digits of a long long value is missing. A sprintf() call can thereby cause a buffer overflow. Exploitation generally requires privileged access to the system, since creating or configuring Device Mapper targets requires appropriate rights. No public exploit or active attacks are known. The flaw has been fixed in the kernel.

Risk score

0
cvss base
0.00
kev bonus
0.00
epss bonus
0.00
poc bonus
0.00
raw before weight
0.00
industry weight
1.10
freshness factor
1.00
exploitability factor
1.00
days old
0.00
vendor mismatch penalty
0.00

Path: operational

ESC