{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89865","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.771Z","datePublished":"2026-09-16T10:31:35.758Z","dateUpdated":"2026-09-16T10:31:35.758Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-16T10:31:35.758Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: qla2xxx: Zero SFP DMA buffer in FRU/I2C bsg handlers\n\nThe FRU and I2C bsg handlers stage their transfer in a DMA_POOL_SIZE\n(256-byte) bounce buffer obtained from dma_pool_alloc(), which does not\nzero the allocation. They initialize only a few leading bytes before\nhanding the buffer to qla2x00_write_sfp().\n\nqla2x00_write_sfp() can override the transfer length with a user-supplied\nvalue:\n\n\tif (len == 1)\n\t\topt |= BIT_0;\n\tif (opt & BIT_0)\n\t\tlen = *sfp;\n\n*sfp is the first byte of the (user-controlled) payload, so len can grow\nup to 255. The device then DMA-reads len bytes from the 256-byte pool\nbuffer. Since only a small prefix was written\n(e.g. MAX_FRU_SIZE == 36 bytes for a FRU version, one byte for a FRU\nstatus register), the hardware reads past the initialized region and\nwrites up to ~219 bytes of stale DMA-pool heap memory to the device\nflash.\n\nAllocate the buffer with dma_pool_zalloc() in all five FRU/I2C handlers\nso any bytes beyond the initialized data are zero rather than stale heap\ncontents."}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/scsi/qla2xxx/qla_bsg.c"],"versions":[{"version":"697a4bc69159c3396035b0506ffa55c4b2d0b1f4","lessThan":"a476377a66897549dd49bee319f4df66623417b7","status":"affected","versionType":"git"},{"version":"697a4bc69159c3396035b0506ffa55c4b2d0b1f4","lessThan":"09703bc7c0be3a7a155b0ff5f21f6765ba3f519c","status":"affected","versionType":"git"},{"version":"697a4bc69159c3396035b0506ffa55c4b2d0b1f4","lessThan":"97c45c75f5cdec96b1a4fba8b1d55d0dd01af1e8","status":"affected","versionType":"git"},{"version":"697a4bc69159c3396035b0506ffa55c4b2d0b1f4","lessThan":"84bde5ce4038d9ad811e5c994305bbfcbd7a9f79","status":"affected","versionType":"git"},{"version":"697a4bc69159c3396035b0506ffa55c4b2d0b1f4","lessThan":"581590f560b74399151b3cbc88574424c2f3d2dc","status":"affected","versionType":"git"},{"version":"697a4bc69159c3396035b0506ffa55c4b2d0b1f4","lessThan":"b157256c28086c434afd70cc78bf9b4d8caf1276","status":"affected","versionType":"git"},{"version":"697a4bc69159c3396035b0506ffa55c4b2d0b1f4","lessThan":"a5501c42256235523c4dddf799f032dfbf4f4c77","status":"affected","versionType":"git"},{"version":"697a4bc69159c3396035b0506ffa55c4b2d0b1f4","lessThan":"b47d4a1547d9ef21b2e9d1a739fe2204d4be05dc","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/scsi/qla2xxx/qla_bsg.c"],"versions":[{"version":"3.2","status":"affected"},{"version":"0","lessThan":"3.2","status":"unaffected","versionType":"semver"},{"version":"5.10.270","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.221","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.188","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.110","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.51","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.5","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.2","versionEndExcluding":"5.10.270"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.2","versionEndExcluding":"5.15.221"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.2","versionEndExcluding":"6.1.188"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.2","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.2","versionEndExcluding":"6.12.110"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.2","versionEndExcluding":"6.18.51"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.2","versionEndExcluding":"7.2.5"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.2","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/a476377a66897549dd49bee319f4df66623417b7"},{"url":"https://git.kernel.org/stable/c/09703bc7c0be3a7a155b0ff5f21f6765ba3f519c"},{"url":"https://git.kernel.org/stable/c/97c45c75f5cdec96b1a4fba8b1d55d0dd01af1e8"},{"url":"https://git.kernel.org/stable/c/84bde5ce4038d9ad811e5c994305bbfcbd7a9f79"},{"url":"https://git.kernel.org/stable/c/581590f560b74399151b3cbc88574424c2f3d2dc"},{"url":"https://git.kernel.org/stable/c/b157256c28086c434afd70cc78bf9b4d8caf1276"},{"url":"https://git.kernel.org/stable/c/a5501c42256235523c4dddf799f032dfbf4f4c77"},{"url":"https://git.kernel.org/stable/c/b47d4a1547d9ef21b2e9d1a739fe2204d4be05dc"}],"title":"scsi: qla2xxx: Zero SFP DMA buffer in FRU/I2C bsg handlers","x_generator":{"engine":"bippy-1.2.0"}}}}