---
cve: "CVE-2026-89846"
severity: "CRITICAL"
cvss: 9.1
epss: "0.7%"
vendor: "Linux"
kev: false
exploited: false
published: "2026-09-16 11:16:51"
tags: [cve, security, critical]
source: tsecurity.de CVE-Dossier
exported: "2026-10-09T15:44:28+02:00"
---

# CVE-2026-89846

> 9.1 CRITICAL

## Beschreibung

In the Linux kernel, the following vulnerability has been resolved:

scsi: qla2xxx: Bound rsp_info_len to avoid OOB sense-data read

In qla2x00_status_entry(), the FWI2 status path advances sense_data and
shrinks par_sense_len by rsp_info_len:

	if (IS_FWI2_CAPABLE(ha)) {
		sense_data += rsp_info_len;
		par_sense_len -= rsp_info_len;
	}

rsp_info_len is a 32-bit value taken directly from the target's FCP
response (sf.rsp_data_len), while par_sense_len is the IOCB data area
size (28 bytes for 24xx, 60 bytes for 29xx). A hostile or buggy target
reporting an rsp_info_len larger than par_sense_len makes the unsigned
subtraction underflow to a huge value and advances sense_data out of
bounds.

The underflowed par_sense_len then defeats the cap in
qla2x00_handle_sense():

	if (sense_len > par_sense_len)
		sense_len = par_sense_len;
	memcpy(cp->sense_buffer, sense_data, sense_len);

so the memcpy reads up to SCSI_SENSE_BUFFERSIZE bytes from the
out-of-bounds sense_data pointer, leaking adjacent response-ring/heap
memory into the command's sense buffer.

Clamp rsp_info_len to par_sense_len before the subtraction so
par_sense_len can never underflow and sense_data stays within the IOCB
data area. The fix sits before the comp_status switch, covering both
qla2x00_handle_sense() call sites.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Keine | good |
| A Verfügbarkeit | Hoch | bad |

## Patch verfügbar (OSV)

- Kernel ≥ 5.10.270
- Kernel ≥ 5.15.221
- Kernel ≥ 6.1.188
- Kernel ≥ 6.6.157
- Kernel ≥ 6.12.110
- Kernel ≥ 6.18.51
- Kernel ≥ 7.2.5

## BSI-Hinweise (deutsch)

- [Linux Kernel: Mehrere Schwachstellen](https://wid.cert-bund.de/portal/wid/sicherheitshinweis/WID-SEC-W-2026-3438) — _BSI-Einstufung: mittel_
  Ein lokaler Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service zu verursachen oder eine nicht näher spezifizierte Auswirkung zu erzielen.

## Referenzen

- <https://git.kernel.org/stable/c/125b12861c726e58448bb95d55b04851fb131d1f>
- <https://git.kernel.org/stable/c/e57ace988bda5693f7b3645f652ea4b4220870ee>
- <https://git.kernel.org/stable/c/6b08c0cb110a1fba92f99d655020198489699815>
- <https://git.kernel.org/stable/c/be75ab791c9b3baca66c70ce03443afebc83acda>
- <https://git.kernel.org/stable/c/ebc41dfc59d190956e0113e8bd90c28f6f21e8b9>
- <https://git.kernel.org/stable/c/d7f7746ff031ae45724881261804f4bf5317c985>
- <https://git.kernel.org/stable/c/f6e8977bce887481b2b2b0e2e14a791270741cfb>
- <https://git.kernel.org/stable/c/ca6d880d6c70cb7946e7b3e05d7285f271b6d99e>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/sicherheitsluecken/cve-2026-89846/) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI WID (CSAF)_
