Description
In the Linux kernel, the following vulnerability has been resolved:

scsi: qla2xxx: Fix FCE trace enable parsing in debugfs

qla2x00_dfs_fce_write() called kstrtoul() with a NULL result pointer,
so a successful parse would dereference NULL and oops. Worse, the int
return value (0 on success, negative errno on failure) was assigned to
the unsigned long enable flag, inverting the intended logic: a valid
number was treated as "disable" while a parse failure enabled FCE.

Parse the value into enable and propagate parse errors to userspace.
Published: 2026-09-16
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply patch
AI Analysis

Impact

A null‑pointer dereference in the qla2xxx SCSI driver causes a kernel crash when a privileged user writes malformed data to the debugfs FCE trace file. The bug also inverts the enable/disable logic due to incorrect handling of the return value, potentially misconfiguring FCE tracing. The result is a local denial of service as the kernel Oopses and may reboot or become unreachable until a reboot occurs.

Affected Systems

Linux kernel builds that include the qla2xxx driver and expose the FCE debugfs interface are affected. Any kernel version prior to the upstream patch referenced in the advisory is vulnerable. Specific kernel releases are not enumerated in the advisory, so all kernels with the unpatched qla2xxx code should be treated as susceptible.

Risk and Exploitability

The EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog, indicating a very low probability of public exploitation. Because the debugfs write operation requires root or equivalent privileges, only a local attacker with sufficient permissions can trigger the fault. The impact is a local kernel crash rather than remote code execution. Consequently, the overall risk is moderate, and applying the upstream fix as soon as possible is strongly recommended.

Generated by OpenCVE AI on September 18, 2026 at 09:04 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the kernel to a version that contains the commit fixing qla2xxx debugfs FCE parsing. This can be achieved by installing the latest distribution update or by manually applying the referenced commit to the source and rebuilding the kernel.
  • If an immediate kernel upgrade is not feasible, remove the qla2xxx debugfs entry (e.g., by deleting the file or ensuring it is not mounted) to prevent any writes that could trigger the fault.
  • Restrict write access to the debugfs interface so that only trusted privileged users can modify it, or disable debugfs entirely on hosts where it is not required.

Generated by OpenCVE AI on September 18, 2026 at 09:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix FCE trace enable parsing in debugfs qla2x00_dfs_fce_write() called kstrtoul() with a NULL result pointer, so a successful parse would dereference NULL and oops. Worse, the int return value (0 on success, negative errno on failure) was assigned to the unsigned long enable flag, inverting the intended logic: a valid number was treated as "disable" while a parse failure enabled FCE. Parse the value into enable and propagate parse errors to userspace.
Title scsi: qla2xxx: Fix FCE trace enable parsing in debugfs
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T10:31:25.069Z

Reserved: 2026-09-11T19:38:34.770Z

Link: CVE-2026-89851

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:16:52.757

Modified: 2026-09-16T11:16:52.757

Link: CVE-2026-89851

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T13:45:15Z

Weaknesses

No weakness.