{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89849","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.770Z","datePublished":"2026-09-16T10:31:23.180Z","dateUpdated":"2026-09-16T14:39:18.117Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-16T14:39:18.117Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: qla2xxx: Reject non-SCSI SRB on status IOCB fast path\n\nqla2x00_status_entry() filters out non-TYPE_SRB entries and the\nSRB_NVME_CMD, SRB_BIDI_CMD and SRB_TM_CMD types, then falls through to a\nSCSI fast path that assumes the command is an SRB_SCSI_CMD. The first\nthing on that path, qla_chk_edif_rx_sa_delete_pending(), and the\nsubsequent handling both evaluate GET_CMD_SP(sp), i.e. sp->u.scmd.cmd.\n\nThe srb u union overlays the SCSI command pointer with other command\nlayouts (bsg_job, iocb_cmd). If firmware delivers an unexpected\nSTATUS_TYPE IOCB for a non-SCSI handle, sp->u.scmd.cmd can read as a\nnon-NULL garbage pointer, bypassing the NULL checks in\nqla_chk_edif_rx_sa_delete_pending() and at the cp == NULL test, and\nleading to a wild pointer dereference.\n\nReject any SRB whose type is not SRB_SCSI_CMD before entering the fast\npath. The outstanding_cmds slot is left untouched so a genuinely\nnon-SCSI command still completes through its proper handler."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:A - qla2xxx processes STATUS_TYPE IOCBs from the Fibre Channel/FCoE HBA response queue in interrupt context. A peer on the same SAN fabric can keep non-SCSI SRBs (login, CT, NACK, NVMe LS) outstanding and drive firmware completions; FC is a non-routable fabric, so Adjacent is the highest defensible vector.\nAC:L - Firmware already completes several non-SCSI types (NVMe, bidirectional, task-management) via STATUS_TYPE, and the SCSI fast path was an unguarded fall-through. Once a STATUS_TYPE IOCB names a non-SCSI handle, the type confusion is deterministic, with no race or layout outside attacker influence.\nPR:N - Fibre Channel has no host authentication by default. Fabric login, nameserver CT, target-mode NACK, and I/O completions are handled in the HBA ISR/DPC with no Linux account or capability required on the victim.\nUI:N - Response-queue processing runs automatically from the HBA interrupt and qla_do_work paths. No victim mount, open, or other user action is required.\nS:U - The type confusion and wild-pointer access occur in the host kernel that owns the qla2xxx driver. This is not a VM escape, IOMMU bypass, or other cross-authority impact.\nC:H - GET_CMD_SP(sp) overlays scsi_cmnd* with other SRB union members (bsg_job*, ctarg.iocb, ntfy, sa_ctl). Treating those live kernel pointers as scsi_cmnd yields wild reads of command and sense fields, a type-confusion primitive that can be leveraged for kernel memory disclosure.\nI:H - The same type confusion writes through the forged scsi_cmnd via scsi_set_resid and memset/memcpy of firmware sense data into cp->sense_buffer. Type confusion with those kernel writes is High integrity and can hijack control flow.\nA:H - Dereferencing the overlaid non-SCSI pointer as scsi_cmnd in interrupt/completion context causes a kernel oops or panic, matching related qla_chk_edif_rx_sa_delete_pending crashes on this path."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/scsi/qla2xxx/qla_dbg.c","drivers/scsi/qla2xxx/qla_isr.c"],"versions":[{"version":"dd30706e73b70d67e88fdaca688db7a3374fd5de","lessThan":"9204fb0888374083be74f799049649a17eab4191","status":"affected","versionType":"git"},{"version":"dd30706e73b70d67e88fdaca688db7a3374fd5de","lessThan":"b7418198b45b327194b97f856fe8ea8daa91f3fd","status":"affected","versionType":"git"},{"version":"dd30706e73b70d67e88fdaca688db7a3374fd5de","lessThan":"8f0e31e7a41376abe7d6ca7cbee07fcf9de071e6","status":"affected","versionType":"git"},{"version":"dd30706e73b70d67e88fdaca688db7a3374fd5de","lessThan":"e38041b47c29316ba79b645e2ae0b713d216b1db","status":"affected","versionType":"git"},{"version":"dd30706e73b70d67e88fdaca688db7a3374fd5de","lessThan":"e93aa3c5125d9a4352ac0fa8ba4a7f8f87881805","status":"affected","versionType":"git"},{"version":"dd30706e73b70d67e88fdaca688db7a3374fd5de","lessThan":"29f1f9ad9e354cd0b6e4f6fc75ba09162d6a04d9","status":"affected","versionType":"git"},{"version":"dd30706e73b70d67e88fdaca688db7a3374fd5de","lessThan":"0f41d07d72f2245208c45374ca8d0a1846cad667","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/scsi/qla2xxx/qla_dbg.c","drivers/scsi/qla2xxx/qla_isr.c"],"versions":[{"version":"5.15","status":"affected"},{"version":"0","lessThan":"5.15","status":"unaffected","versionType":"semver"},{"version":"5.15.221","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.188","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.110","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.51","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.5","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.15","versionEndExcluding":"5.15.221"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.15","versionEndExcluding":"6.1.188"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.15","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.15","versionEndExcluding":"6.12.110"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.15","versionEndExcluding":"6.18.51"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.15","versionEndExcluding":"7.2.5"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.15","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/9204fb0888374083be74f799049649a17eab4191"},{"url":"https://git.kernel.org/stable/c/b7418198b45b327194b97f856fe8ea8daa91f3fd"},{"url":"https://git.kernel.org/stable/c/8f0e31e7a41376abe7d6ca7cbee07fcf9de071e6"},{"url":"https://git.kernel.org/stable/c/e38041b47c29316ba79b645e2ae0b713d216b1db"},{"url":"https://git.kernel.org/stable/c/e93aa3c5125d9a4352ac0fa8ba4a7f8f87881805"},{"url":"https://git.kernel.org/stable/c/29f1f9ad9e354cd0b6e4f6fc75ba09162d6a04d9"},{"url":"https://git.kernel.org/stable/c/0f41d07d72f2245208c45374ca8d0a1846cad667"}],"title":"scsi: qla2xxx: Reject non-SCSI SRB on status IOCB fast path","x_generator":{"engine":"bippy-1.2.0"}}}}