PT-2026-93484 · Linux · Linux Kernel

CVE-2026-89843

·

Published

2026-09-16

·

Updated

2026-09-24

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An information leak exists in the qla2xxx SCSI driver where several bsg handlers use an uninitialized 256-byte buffer bsg[DMA POOL SIZE]. When a user-supplied request payload is shorter than the buffer size, the remaining space retains stale stack data. The functions qla2x00 read fru status() and qla2x00 read i2c() subsequently copy the entire buffer back to the reply payload, exposing this uninitialized memory to user space. Additionally, write and update paths may send these uninitialized fields to the device.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-101598
CVE-2026-89843
OPENSUSE-SU-2026:11880-1

Affected Products

Linux Kernel