Description
In the Linux kernel, the following vulnerability has been resolved:

scsi: qla2xxx: Zero-init bsg stack buffers to avoid info leak

Several bsg handlers stage their request/reply in an uninitialized 256-byte
on-stack buffer (uint8_t bsg[DMA_POOL_SIZE]) and fill it via
sg_copy_to_buffer(), which only copies as many bytes as the user-supplied
request payload. When the request is shorter than the structure, the
remainder of the buffer is left holding stale stack data.

qla2x00_read_fru_status() and qla2x00_read_i2c() then copy the full
structure back to the reply payload with sg_copy_from_buffer(), leaking the
uninitialized stack bytes to user space. The write/update paths do not copy
the buffer back, but can feed uninitialized fields to the device.

Zero the stack buffer at declaration in all five handlers, mirroring the
heap kzalloc() approach, so short requests can no longer expose stale
memory.
Published: 2026-09-16
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Update Kernel
AI Analysis

Impact

The qla2xxx SCSI driver in the Linux kernel allocates 256‑byte buffers on the stack for several bsg handlers. The driver copies only the user‑supplied request payload into this buffer, leaving any remaining bytes uninitialized. When the driver later copies the full buffer back to the reply payload, the stale memory contents become visible to user space. This allows an attacker to read kernel memory that was never intended to be exposed, resulting in an information‑leak vulnerability.

Affected Systems

All Linux kernel releases that include the qla2xxx SCSI driver before the commit that zero‑inits the stack buffer are affected. The vulnerability applies to the Linux kernel product, regardless of vendor, as long as the uninitialized stack buffer is present in the bsg handlers.

Risk and Exploitability

The flaw can be triggered from user space by interacting with the affected SCSI device; the attacker does not need elevated privileges beyond access to the device. The EPSS score indicates a very low probability of exploitation in the near term, and the vulnerability is not currently listed in CISA's KEV catalog. Nevertheless, any untrusted user who can issue SCSI requests to the device can leak portions of kernel memory, potentially exposing sensitive data.

Generated by OpenCVE AI on September 18, 2026 at 09:53 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes the zero‑initialization fix for the qla2xxx bsg handlers
  • If a kernel update is not feasible, restrict access to the affected SCSI device to privileged users or use device‑level ACLs to prevent untrusted users from sending requests
  • If disabling the device is acceptable, unbind or remove the qla2xxx SCSI device from user space until a patch can be applied

Generated by OpenCVE AI on September 18, 2026 at 09:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 10:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-457

Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Zero-init bsg stack buffers to avoid info leak Several bsg handlers stage their request/reply in an uninitialized 256-byte on-stack buffer (uint8_t bsg[DMA_POOL_SIZE]) and fill it via sg_copy_to_buffer(), which only copies as many bytes as the user-supplied request payload. When the request is shorter than the structure, the remainder of the buffer is left holding stale stack data. qla2x00_read_fru_status() and qla2x00_read_i2c() then copy the full structure back to the reply payload with sg_copy_from_buffer(), leaking the uninitialized stack bytes to user space. The write/update paths do not copy the buffer back, but can feed uninitialized fields to the device. Zero the stack buffer at declaration in all five handlers, mirroring the heap kzalloc() approach, so short requests can no longer expose stale memory.
Title scsi: qla2xxx: Zero-init bsg stack buffers to avoid info leak
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T10:31:17.474Z

Reserved: 2026-09-11T19:38:34.770Z

Link: CVE-2026-89843

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:16:51.157

Modified: 2026-09-16T11:16:51.157

Link: CVE-2026-89843

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T10:00:06Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-457

    Use of Uninitialized Variable