CVE-2026-89856

Source
https://cve.org/CVERecord?id=CVE-2026-89856
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89856.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-89856
Downstream
Published
2026-09-16T10:31:29Z
Modified
2026-09-17T03:47:27Z
Severity
  • 8.4 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
scsi: qla2xxx: Clamp MSI-X derived queue counts to avoid truncation
Details

In the Linux kernel, the following vulnerability has been resolved:

scsi: qla2xxx: Clamp MSI-X derived queue counts to avoid truncation

ha->msix_count is u16, but ha->max_req_queues, ha->max_rsp_queues and ha->max_qpairs are u8. Deriving the queue count as "ha->max_req_queues = ha->msix_count - 1" therefore truncates: a board (or a misconfigured/malicious hot-plugged device) advertising 257 MSI-X vectors yields msix_count - 1 == 256, which truncates to 0. An MSI-X count of 1 zeroes it as well, and in target mode the subsequent "ha->max_req_queues--" then underflows 0 to 255.

When the count is 0, qla2x00_alloc_queues() calls kzalloc_objs(struct req_que *, 0), which returns ZERO_SIZE_PTR. That is not NULL, so the allocation check passes and the following "ha->req_q_map[0] = req" dereferences ZERO_SIZE_PTR, corrupting memory or crashing the kernel.

Add qla_calc_queue_count() to clamp the derived value into [1, QLA_MAX_QUEUES - 1] so it always fits in u8 and is never zero, and use it at all three derivation sites (qla25xx_iospace_config(), qla83xx_iospace_config() and qla24xx_enable_msix()). Also guard the target-mode decrement so it cannot reintroduce a zero (which would in turn underflow max_qpairs).

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89856.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
d74595278f4ab192af66d9e60a9087464638beee
Fixed
cf623d32761b00f221a9cfded3303d56e84b429d
Fixed
9eeddbeaa896f39d943644b16d83a6ad0ceab255
Fixed
802068b9b683b8008fcccbf6e9ad133e597ec87c
Fixed
e80adfeac61b4d5db7ffe0f5af43999c33a4145e
Fixed
2efe50b2da829909023de4a2eb87badb7cfa53cc
Fixed
7a448f5ed0b283dbde4e9183dd1e98c221432dab
Fixed
33c77254e6e91f37c72c7fad4051777452b10de8
Fixed
ebfd35c64433821bd5619a6d07ccc2df8b5b1de3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89856.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.10.0
Fixed
5.10.270
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.221
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.188
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.157
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.110
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.51
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89856.json"