Description
In the Linux kernel, the following vulnerability has been resolved:

s390/dasd: Propagate partial completion length across ERP recovery

dasd_default_erp_postaction() copies the timing and device state from
the finished ERP request back to the original request but drops
proc_bytes. A request that was partially completed, an ESE read of a
not-yet-allocated track returns fewer bytes than requested, and then
recovered through the ERP chain loses its partial-completion length.
__dasd_cleanup_cqr() then sees proc_bytes == 0 and completes the whole
request instead of requeueing the remainder, silently returning zeroed
data for the part that was never read.

Carry proc_bytes over to the original request like the other
per-request state.
Published: 2026-09-11
Score: 7 High
EPSS: < 1% Very Low
KEV: No
Impact: Data Integrity
Action: Patch Kernel
AI Analysis

Impact

The Linux kernel s390/dasd subsystem contains a flaw where a partially completed ERP request inadvertently loses its proc_bytes value during recovery. When the cleanup routine later interprets this zero value, it mistakenly treats the entire request as complete and zero‑fills any remaining unread data. The result is silent corruption of data read from DASD devices, compromising data integrity without triggering error codes or crashes.

Affected Systems

The vulnerability affects the s390 DASD driver within the Linux kernel. Any system running a kernel version that contains the unpatched code path and that relies on the default s390 kernel is potentially at risk. No specific version range is listed, so all affected releases lacking the fix should be considered vulnerable.

Risk and Exploitability

The CVSS score of 7.0 indicates moderate to high severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires the ability to trigger ERP operations on a DASD device, so widespread abuse remains limited. However, environments that allow untrusted users to issue reads on DASD devices face potential silent data corruption and loss of confidentiality or integrity.

Generated by OpenCVE AI on September 21, 2026 at 01:12 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the fix for the missing proc_bytes propagation in the s390 DASD driver.
  • Limit access to DASD devices so that only privileged, trusted processes can perform ERP operations.
  • Implement data integrity checks (e.g., checksums or cryptographic hashes) on data read from DASD to detect silent corruption.

Generated by OpenCVE AI on September 21, 2026 at 01:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 14 Sep 2026 12:30:00 +0000


Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.2, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:H'}

cvssV3_1

{'score': 7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-908
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.2, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: s390/dasd: Propagate partial completion length across ERP recovery dasd_default_erp_postaction() copies the timing and device state from the finished ERP request back to the original request but drops proc_bytes. A request that was partially completed, an ESE read of a not-yet-allocated track returns fewer bytes than requested, and then recovered through the ERP chain loses its partial-completion length. __dasd_cleanup_cqr() then sees proc_bytes == 0 and completes the whole request instead of requeueing the remainder, silently returning zeroed data for the part that was never read. Carry proc_bytes over to the original request like the other per-request state.
Title s390/dasd: Propagate partial completion length across ERP recovery
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T11:59:56.742Z

Reserved: 2026-09-11T19:38:34.707Z

Link: CVE-2026-89456

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:26.387

Modified: 2026-09-14T13:19:01.933

Link: CVE-2026-89456

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:43:20Z

Links: CVE-2026-89456 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T01:15:03Z

Weaknesses
  • CWE-908

    Use of Uninitialized Resource