PT-2026-93500 · Linux · Linux Kernel
CVE-2026-89859
·
Published
2026-09-16
·
Updated
2026-09-25
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An information leak exists in the scsi qla2xxx driver. The function
qla2x00 do dport diagnostics() uses kmalloc obj() to allocate a qla dport diag response buffer without zeroing it. Because sg copy to buffer() only fills the buffer based on the user request payload and qla26xx dport diagnostics() only zeroes the dd->buf field, the options and unused[] fields remain uninitialized. Consequently, these fields are copied back to user space via sg copy from buffer(), leaking kernel heap contents.Recommendations
Update the Linux kernel to a version where
qla2x00 do dport diagnostics() uses kzalloc obj() for buffer allocation.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel