PT-2026-93500 · Linux · Linux Kernel

CVE-2026-89859

·

Published

2026-09-16

·

Updated

2026-09-25

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An information leak exists in the scsi qla2xxx driver. The function qla2x00 do dport diagnostics() uses kmalloc obj() to allocate a qla dport diag response buffer without zeroing it. Because sg copy to buffer() only fills the buffer based on the user request payload and qla26xx dport diagnostics() only zeroes the dd->buf field, the options and unused[] fields remain uninitialized. Consequently, these fields are copied back to user space via sg copy from buffer(), leaking kernel heap contents.
Recommendations Update the Linux kernel to a version where qla2x00 do dport diagnostics() uses kzalloc obj() for buffer allocation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-101171
CVE-2026-89859
OESA-2026-4039
OPENSUSE-SU-2026:11880-1

Affected Products

Linux Kernel