CVE-2026-89859

Source
https://cve.org/CVERecord?id=CVE-2026-89859
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89859.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-89859
Downstream
Related
Published
2026-09-16T10:31:31Z
Modified
2026-10-05T02:30:21Z
Summary
scsi: qla2xxx: Zero dport diagnostics buffer to avoid info leak
Details

In the Linux kernel, the following vulnerability has been resolved:

scsi: qla2xxx: Zero dport diagnostics buffer to avoid info leak

qla2x00_do_dport_diagnostics() allocates the qla_dport_diag response buffer with kmalloc_obj() (non-zeroing) and, on success, copies the full sizeof(*dd) back to user space via sg_copy_from_buffer(). The inbound sg_copy_to_buffer() only fills as many bytes as the user request payload provides, and qla26xx_dport_diagnostics() zeroes only dd->buf. The options and unused[] fields are therefore copied out uninitialized, leaking kernel heap contents to user space.

Allocate with kzalloc_obj(), matching qla2x00_do_dport_diagnostics_v2().

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89859.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
ec89146215d124c429bff84b498dccdc4919ffa7
Fixed
5dfc77099c7d9fde9520a229794b0154d7ccccc1
Fixed
d6e2411516bb95e52cb74c9c56b60ad2548a2730
Fixed
9fc03be982763a131913f84fe73b240ae45bca37
Fixed
a152edab3854f01dd2daf3eaf8f32cbabdb3834e

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89859.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.8.0
Fixed
6.12.112
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.53
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89859.json"