{"id":"CVE-2026-89865","summary":"scsi: qla2xxx: Zero SFP DMA buffer in FRU/I2C bsg handlers","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: qla2xxx: Zero SFP DMA buffer in FRU/I2C bsg handlers\n\nThe FRU and I2C bsg handlers stage their transfer in a DMA_POOL_SIZE\n(256-byte) bounce buffer obtained from dma_pool_alloc(), which does not\nzero the allocation. They initialize only a few leading bytes before\nhanding the buffer to qla2x00_write_sfp().\n\nqla2x00_write_sfp() can override the transfer length with a user-supplied\nvalue:\n\n\tif (len == 1)\n\t\topt |= BIT_0;\n\tif (opt & BIT_0)\n\t\tlen = *sfp;\n\n*sfp is the first byte of the (user-controlled) payload, so len can grow\nup to 255. The device then DMA-reads len bytes from the 256-byte pool\nbuffer. Since only a small prefix was written\n(e.g. MAX_FRU_SIZE == 36 bytes for a FRU version, one byte for a FRU\nstatus register), the hardware reads past the initialized region and\nwrites up to ~219 bytes of stale DMA-pool heap memory to the device\nflash.\n\nAllocate the buffer with dma_pool_zalloc() in all five FRU/I2C handlers\nso any bytes beyond the initialized data are zero rather than stale heap\ncontents.","modified":"2026-09-18T03:48:33.653409499Z","published":"2026-09-16T10:31:35.758Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89865.json","cna_assigner":"Linux"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/09703bc7c0be3a7a155b0ff5f21f6765ba3f519c"},{"type":"WEB","url":"https://git.kernel.org/stable/c/581590f560b74399151b3cbc88574424c2f3d2dc"},{"type":"WEB","url":"https://git.kernel.org/stable/c/84bde5ce4038d9ad811e5c994305bbfcbd7a9f79"},{"type":"WEB","url":"https://git.kernel.org/stable/c/97c45c75f5cdec96b1a4fba8b1d55d0dd01af1e8"},{"type":"WEB","url":"https://git.kernel.org/stable/c/a476377a66897549dd49bee319f4df66623417b7"},{"type":"WEB","url":"https://git.kernel.org/stable/c/a5501c42256235523c4dddf799f032dfbf4f4c77"},{"type":"WEB","url":"https://git.kernel.org/stable/c/b157256c28086c434afd70cc78bf9b4d8caf1276"},{"type":"WEB","url":"https://git.kernel.org/stable/c/b47d4a1547d9ef21b2e9d1a739fe2204d4be05dc"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89865.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89865"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"697a4bc69159c3396035b0506ffa55c4b2d0b1f4"},{"fixed":"a476377a66897549dd49bee319f4df66623417b7"},{"fixed":"09703bc7c0be3a7a155b0ff5f21f6765ba3f519c"},{"fixed":"97c45c75f5cdec96b1a4fba8b1d55d0dd01af1e8"},{"fixed":"84bde5ce4038d9ad811e5c994305bbfcbd7a9f79"},{"fixed":"581590f560b74399151b3cbc88574424c2f3d2dc"},{"fixed":"b157256c28086c434afd70cc78bf9b4d8caf1276"},{"fixed":"a5501c42256235523c4dddf799f032dfbf4f4c77"},{"fixed":"b47d4a1547d9ef21b2e9d1a739fe2204d4be05dc"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89865.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.2.0"},{"fixed":"5.10.270"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.11.0"},{"fixed":"5.15.221"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.16.0"},{"fixed":"6.1.188"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.2.0"},{"fixed":"6.6.157"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.12.110"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.51"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.2.5"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89865.json"}}],"schema_version":"1.9.0"}