PT-2026-93487 · Linux+1 · Linux Kernel+1
CVE-2026-89846
·
Published
2026-09-16
·
Updated
2026-09-25
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An out-of-bounds read exists in the
qla2x00 status entry() function. The issue occurs when the FWI2 status path advances sense data and reduces par sense len by the value of rsp info len. Because rsp info len is a 32-bit value taken directly from the target's FCP response, a malicious or buggy target can report a value larger than par sense len. This causes an unsigned subtraction underflow, resulting in a very large value for par sense len and moving the sense data pointer out of bounds. Consequently, the qla2x00 handle sense() function fails to properly cap the length, allowing memcpy() to read up to SCSI SENSE BUFFERSIZE bytes from the out-of-bounds pointer, which leaks adjacent response-ring or heap memory into the command's sense buffer.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel
Rocky Linux