CVE-2026-89575
A NVD · · CVE-2026-89575
Admiralty grading (A–F · 1–6)
Source reliability
- A Completely reliable
- B Usually reliable
- C Fairly reliable
- D Not usually reliable
- E Unreliable
- F Cannot be judged
Information credibility
- 1 Confirmed
- 2 Probably true
- 3 Possibly true
- 4 Doubtful
- 5 Improbable
- 6 Cannot be judged
NATO Admiralty (AJP-2.1) grades confidence, independent of the risk score. Cross-source corroboration isn't tracked for non-CVE news, so single-source items are capped at a lower credibility number; a low number does not imply low quality.
Key metrics
- EPSS
- 0%
Key insight
Pure patch information with no indication of active exploitation or strategic relevance.
Description
The vulnerability CVE-2026-89575 affects the Linux kernel in the Device Mapper RAID1 target. In the function build_constructor_string(), the buffer for the string is not sufficiently sized, so the terminating NUL after up to 20 decimal digits of a long long value is missing. A sprintf() call can thereby cause a buffer overflow. Exploitation generally requires privileged access to the system, since creating or configuring Device Mapper targets requires appropriate rights. No public exploit or active attacks are known. The flaw has been fixed in the kernel.
Risk score
- cvss base
- 0.00
- kev bonus
- 0.00
- epss bonus
- 0.00
- poc bonus
- 0.00
- raw before weight
- 0.00
- industry weight
- 1.10
- freshness factor
- 1.00
- exploitability factor
- 1.00
- days old
- 0.00
- vendor mismatch penalty
- 0.00
Path: operational