← All Advisories

CVE-2026-89859

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-89859

Key Details

CVECVE-2026-89859
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

scsi: qla2xxx: Zero dport diagnostics buffer to avoid info leak

qla2x00_do_dport_diagnostics() allocates the qla_dport_diag response

buffer with kmalloc_obj() (non-zeroing) and, on success, copies the full

sizeof(*dd) back to user space via sg_copy_from_buffer(). The inbound

sg_copy_to_buffer() only fills as many bytes as the user request payload

provides, and qla26xx_dport_diagnostics() zeroes only dd->buf. The

options and unused[] fields are therefore copied out uninitialized,

leaking kernel heap contents to user space.

Allocate with kzalloc_obj(), matching qla2x00_do_dport_diagnostics_v2(). (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-89859
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-89859