CVE-2026-89865
In the Linux kernel, the following vulnerability has been resolved:
scsi: qla2xxx: Zero SFP DMA buffer in FRU/I2C bsg handlers
The FRU and I2C bsg handlers stage their transfer in a DMA_POOL_SIZE (256-byte) bounce buffer obtained from dma_pool_alloc(), which does not zero the allocation. They initialize only a few leading bytes before handing the buffer to qla2x00_write_sfp().
qla2x00_write_sfp() can override the transfer length with a user-supplied value:
*sfp is the first byte of the (user-controlled) payload, so len can grow up to 255. The device then DMA-reads len bytes from the 256-byte pool buffer. Since only a small prefix was written (e.g.
Leer descripción completaMostrar menos
MAX_FRU_SIZE == 36 bytes for a FRU version, one byte for a FRU status register), the hardware reads past the initialized region and writes up to ~219 bytes of stale DMA-pool heap memory to the device flash.
Allocate the buffer with dma_pool_zalloc() in all five FRU/I2C handlers so any bytes beyond the initialized data are zero rather than stale heap contents.
Detalles técnicos trazas, registros y código del informe original
if (len == 1) opt |= BIT_0; if (opt & BIT_0) len = *sfp;
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.21%
- Percentil entre todas las CVEs puntuadas: 10
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/09703bc7c0be3a7a155b0ff5f21f6765ba3f519c
- https://git.kernel.org/stable/c/581590f560b74399151b3cbc88574424c2f3d2dc
- https://git.kernel.org/stable/c/84bde5ce4038d9ad811e5c994305bbfcbd7a9f79
- https://git.kernel.org/stable/c/97c45c75f5cdec96b1a4fba8b1d55d0dd01af1e8
- https://git.kernel.org/stable/c/a476377a66897549dd49bee319f4df66623417b7
- https://git.kernel.org/stable/c/a5501c42256235523c4dddf799f032dfbf4f4c77
- https://git.kernel.org/stable/c/b157256c28086c434afd70cc78bf9b4d8caf1276
- https://git.kernel.org/stable/c/b47d4a1547d9ef21b2e9d1a739fe2204d4be05dc
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-89865",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "697a4bc69159c3396035b0506ffa55c4b2d0b1f4",
"lessThan": "a476377a66897549dd49bee319f4df66623417b7",
"versionType": "git"
},
{
"status": "affected",
"version": "697a4bc69159c3396035b0506ffa55c4b2d0b1f4",
"lessThan": "09703bc7c0be3a7a155b0ff5f21f6765ba3f519c",
"versionType": "git"
},
{
"status": "affected",
"version": "697a4bc69159c3396035b0506ffa55c4b2d0b1f4",
"lessThan": "97c45c75f5cdec96b1a4fba8b1d55d0dd01af1e8",
"versionType": "git"
},
{
"status": "affected",
"version": "697a4bc69159c3396035b0506ffa55c4b2d0b1f4",
"lessThan": "84bde5ce4038d9ad811e5c994305bbfcbd7a9f79",
"versionType": "git"
},
{
"status": "affected",
"version": "697a4bc69159c3396035b0506ffa55c4b2d0b1f4",
"lessThan": "581590f560b74399151b3cbc88574424c2f3d2dc",
"versionType": "git"
},
{
"status": "affected",
"version": "697a4bc69159c3396035b0506ffa55c4b2d0b1f4",
"lessThan": "b157256c28086c434afd70cc78bf9b4d8caf1276",
"versionType": "git"
},
{
"status": "affected",
"version": "697a4bc69159c3396035b0506ffa55c4b2d0b1f4",
"lessThan": "a5501c42256235523c4dddf799f032dfbf4f4c77",
"versionType": "git"
},
{
"status": "affected",
"version": "697a4bc69159c3396035b0506ffa55c4b2d0b1f4",
"lessThan": "b47d4a1547d9ef21b2e9d1a739fe2204d4be05dc",
"versionType": "git"
}
],
"programFiles": [
"drivers/scsi/qla2xxx/qla_bsg.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "3.2"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "3.2",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.10.270",
"versionType": "semver",
"lessThanOrEqual": "5.10.*"
},
{
"status": "unaffected",
"version": "5.15.221",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.188",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.157",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.110",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.51",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2.5",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/scsi/qla2xxx/qla_bsg.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-16T11:16:54.610",
"references": [
{
"url": "https://git.kernel.org/stable/c/09703bc7c0be3a7a155b0ff5f21f6765ba3f519c",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/581590f560b74399151b3cbc88574424c2f3d2dc",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/84bde5ce4038d9ad811e5c994305bbfcbd7a9f79",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/97c45c75f5cdec96b1a4fba8b1d55d0dd01af1e8",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/a476377a66897549dd49bee319f4df66623417b7",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/a5501c42256235523c4dddf799f032dfbf4f4c77",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/b157256c28086c434afd70cc78bf9b4d8caf1276",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/b47d4a1547d9ef21b2e9d1a739fe2204d4be05dc",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: qla2xxx: Zero SFP DMA buffer in FRU/I2C bsg handlers\n\nThe FRU and I2C bsg handlers stage their transfer in a DMA_POOL_SIZE\n(256-byte) bounce buffer obtained from dma_pool_alloc(), which does not\nzero the allocation. They initialize only a few leading bytes before\nhanding the buffer to qla2x00_write_sfp().\n\nqla2x00_write_sfp() can override the transfer length with a user-supplied\nvalue:\n\n\tif (len == 1)\n\t\topt |= BIT_0;\n\tif (opt & BIT_0)\n\t\tlen = *sfp;\n\n*sfp is the first byte of the (user-controlled) payload, so len can grow\nup to 255. The device then DMA-reads len bytes from the 256-byte pool\nbuffer. Since only a small prefix was written\n(e.g. MAX_FRU_SIZE == 36 bytes for a FRU version, one byte for a FRU\nstatus register), the hardware reads past the initialized region and\nwrites up to ~219 bytes of stale DMA-pool heap memory to the device\nflash.\n\nAllocate the buffer with dma_pool_zalloc() in all five FRU/I2C handlers\nso any bytes beyond the initialized data are zero rather than stale heap\ncontents."
}
],
"lastModified": "2026-09-16T11:16:54.610",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}