PT-2026-93487 · Linux+1 · Linux Kernel+1

CVE-2026-89846

·

Published

2026-09-16

·

Updated

2026-09-25

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An out-of-bounds read exists in the qla2x00 status entry() function. The issue occurs when the FWI2 status path advances sense data and reduces par sense len by the value of rsp info len. Because rsp info len is a 32-bit value taken directly from the target's FCP response, a malicious or buggy target can report a value larger than par sense len. This causes an unsigned subtraction underflow, resulting in a very large value for par sense len and moving the sense data pointer out of bounds. Consequently, the qla2x00 handle sense() function fails to properly cap the length, allowing memcpy() to read up to SCSI SENSE BUFFERSIZE bytes from the out-of-bounds pointer, which leaks adjacent response-ring or heap memory into the command's sense buffer.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

ALSA-2026:71016
ALSA-2026:71213
ALSA-2026:71232
ALSA-2026:71233
AZL-101637
CVE-2026-89846
OESA-2026-4039
OPENSUSE-SU-2026:11880-1

Affected Products

Linux Kernel
Rocky Linux