{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89586","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.729Z","datePublished":"2026-09-11T19:44:51.322Z","dateUpdated":"2026-09-14T12:01:13.899Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-14T12:01:13.899Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nata: libata-scsi: fix DSM TRIM for sector sizes larger than 2048 bytes\n\nata_scsi_write_same_xlat() translates a SCSI WRITE SAME command with the\nUNMAP bit set into an ATA DATA SET MANAGEMENT TRIM command.  The TRIM\ndescriptor is built by ata_format_dsm_trim_descr() into the 2048-byte\nata_scsi_rbuf staging buffer, and the number of bytes copied is compared\nagainst the logical sector size by the caller:\n\n\tsize = ata_format_dsm_trim_descr(scmd, trmax, block, n_block);\n\tif (size != len)\t\t/* len == sdp->sector_size */\n\t\tgoto invalid_param_len;\n\nata_format_dsm_trim_descr() clamps the copy length to ATA_SCSI_RBUF_SIZE\n(2048).  On a device whose logical sector size exceeds that (e.g. a 4Kn\ndevice, where sector_size == 4096) the function can never return more than\n2048, while the caller expects it to return sector_size.  The comparison\ntherefore always fails, so every TRIM is rejected with \"Parameter list\nlength error\" and WARN_ON() splats on each attempt.  TRIM / discard is\nthus completely broken on such devices.\n\nThe descriptor was incorrectly sized from the logical sector size.  A DSM\nTRIM payload is a list of 512-byte pages, each holding up to\nATA_MAX_TRIM_RNUM (64) LBA Range Entries, and is independent of the logical\nsector size.  The Block Limits VPD page already advertises a single such\npage as the maximum WRITE SAME length (65535 * ATA_MAX_TRIM_RNUM logical\nblocks), so the block layer never sends a request that needs more than one\npage.\n\nEmit exactly one 512-byte page, independent of the logical sector size,\nand transfer only that page (COUNT == 1).  For a 512-byte-sector device\nthis is unchanged; devices with larger logical sectors now work instead of\nfailing every TRIM."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","baseScore":8.2,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:N - SATA/AHCI volumes commonly back NAS/SAN LUNs. Remote iSCSI UNMAP (target_core iblock_execute_unmap()/blkdev_issue_discard()), NFSv4.2 DEALLOCATE (nfsd4_deallocate), and ksmbd FSCTL_SET_ZERO_DATA issue REQ_OP_DISCARD that sd translates to WRITE SAME(16) UNMAP, reaching ata_scsi_write_same_xlat() without local shell access.\nAC:L - On a 4Kn ATA device with TRIM (logical sector_size>2048), every block-layer discard deterministically hits WARN_ON(len>ATA_SCSI_RBUF_SIZE) in ata_format_dsm_trim_descr() then fails size!=sector_size. The attacker fully controls UNMAP/discard issuance; no race or uncontrollable memory layout is required.\nPR:N - Unauthenticated iSCSI/NVMe-oF UNMAP and guest NFS/SMB hole-punch need no Linux UID or capability on the target. The same discard path is also reachable locally by an unprivileged writer via fallocate(PUNCH_HOLE) on discard-mounted filesystems, so Privileges Required is None rather than Low or High.\nUI:N - The attacker or ordinary storage clients issue UNMAP, NFSv4.2 DEALLOCATE, hole-punch, BLKDISCARD, or mount-discard/fstrim I/O themselves. No separate victim click, mount, or confirmation is required at exploit time.\nS:U - The WARN_ON splat, kernel log disclosure, and rejected TRIM remain inside the host kernel and the affected ATA device. The defect does not escape a VM, bypass an IOMMU/DMA boundary, or otherwise cross a separate security authority.\nC:L - WARN_ON() (not WARN_ON_ONCE) calls warn_slowpath()/dump_stack() on every TRIM, disclosing kernel text addresses and limited layout in dmesg when kptr_restrict is relaxed. The rbuf length clamp prevents an out-of-bounds read, so this is not an arbitrary memory-disclosure primitive.\nI:N - After the warning, size!=sector_size takes invalid_param_len and returns a SCSI CHECK CONDITION without issuing DSM TRIM or writing kernel objects, user data, or device LBAs. Passthrough WRITE SAME is rejected, so there is no write or code-execution primitive.\nA:H - WARN_ON() taints the kernel and panics when panic_on_warn is set or warn_limit is exceeded. Because it is not WARN_ON_ONCE, a remote initiator can repeat UNMAP to flood logs and force a host panic, and TRIM/discard is completely broken on 4Kn ATA volumes."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/ata/libata-scsi.c"],"versions":[{"version":"ef2d7392c4ece5c3cd12a6c7ca9366cd8f189aff","lessThan":"07975b8daa3b0ab3cbc02cc48ea7bc48fadcec53","status":"affected","versionType":"git"},{"version":"ef2d7392c4ece5c3cd12a6c7ca9366cd8f189aff","lessThan":"b7b5ab2df325ffbbad7ca2debaa071e024d68cb5","status":"affected","versionType":"git"},{"version":"ef2d7392c4ece5c3cd12a6c7ca9366cd8f189aff","lessThan":"07baa310ea3224a7044b1ca84796bb37a235af1f","status":"affected","versionType":"git"},{"version":"ef2d7392c4ece5c3cd12a6c7ca9366cd8f189aff","lessThan":"977554ed91b54075fbc0bac536316b4841ef6258","status":"affected","versionType":"git"},{"version":"ef2d7392c4ece5c3cd12a6c7ca9366cd8f189aff","lessThan":"04e2befe25792f2e90097f284d7e86fc6bcfe928","status":"affected","versionType":"git"},{"version":"ef2d7392c4ece5c3cd12a6c7ca9366cd8f189aff","lessThan":"c2e3dccd6870659851eaa4c12ab16418b8e3040a","status":"affected","versionType":"git"},{"version":"ef2d7392c4ece5c3cd12a6c7ca9366cd8f189aff","lessThan":"4a4268a0b0a595bd9534cf9c7fda93775a7d8a0d","status":"affected","versionType":"git"},{"version":"ef2d7392c4ece5c3cd12a6c7ca9366cd8f189aff","lessThan":"79cce911e623c0baa0fde307ce3a434e084b881a","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/ata/libata-scsi.c"],"versions":[{"version":"4.9","status":"affected"},{"version":"0","lessThan":"4.9","status":"unaffected","versionType":"semver"},{"version":"5.10.270","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.221","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.188","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.109","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.50","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.9","versionEndExcluding":"5.10.270"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.9","versionEndExcluding":"5.15.221"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.9","versionEndExcluding":"6.1.188"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.9","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.9","versionEndExcluding":"6.12.109"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.9","versionEndExcluding":"6.18.50"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.9","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.9","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/07975b8daa3b0ab3cbc02cc48ea7bc48fadcec53"},{"url":"https://git.kernel.org/stable/c/b7b5ab2df325ffbbad7ca2debaa071e024d68cb5"},{"url":"https://git.kernel.org/stable/c/07baa310ea3224a7044b1ca84796bb37a235af1f"},{"url":"https://git.kernel.org/stable/c/977554ed91b54075fbc0bac536316b4841ef6258"},{"url":"https://git.kernel.org/stable/c/04e2befe25792f2e90097f284d7e86fc6bcfe928"},{"url":"https://git.kernel.org/stable/c/c2e3dccd6870659851eaa4c12ab16418b8e3040a"},{"url":"https://git.kernel.org/stable/c/4a4268a0b0a595bd9534cf9c7fda93775a7d8a0d"},{"url":"https://git.kernel.org/stable/c/79cce911e623c0baa0fde307ce3a434e084b881a"}],"title":"ata: libata-scsi: fix DSM TRIM for sector sizes larger than 2048 bytes","x_generator":{"engine":"bippy-1.2.0"}}}}