Description
In the Linux kernel, the following vulnerability has been resolved:

scsi: qla2xxx: Zero mailbox struct in qla2x00_get_firmware_state()

The mbx_cmd_t is allocated on the stack but left uninitialized.
qla2x00_mailbox_command() has several early-return paths (PCI permanent
failure, device failed, EEH busy, ISP abort pending, mailbox access
timeout, purge mbox) that return without writing the input mailbox
registers back into mcp->mb[]. qla2x00_get_firmware_state() then
unconditionally copies mcp->mb[1..6] (and mb[12]) into the caller's
states[] array regardless of the return value.

On such a failure the copied values are uninitialized kernel stack
memory, which is then exposed to userspace via the fw_state and
mpi_fw_state sysfs handlers. Zero the mailbox struct so a failed query
yields deterministic zeroed state instead of leaking stack contents.
Published: 2026-09-16
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Apply Patch
AI Analysis

Impact

The vulnerability arises when the QLogic qla2xxx SCSI driver copies uninitialized stack data into user‑visible sysfs files. This uninitialized mailbox structure is returned when certain error conditions occur, allowing a local user to read kernel stack contents through the fw_state and mpi_fw_state sysfs entries. The flaw is a classic Uninitialized Local Variable vulnerability (CWE‑457), resulting in information disclosure of potentially sensitive kernel data.

Affected Systems

The flaw affects the Linux kernel’s qla2xxx SCSI driver, which is part of the standard kernel tree. No specific kernel version ranges are listed in the advisory, so any kernel that includes the unpatched qla2xxx driver code may be affected. Operating systems that ship with this driver unchanged are at risk.

Risk and Exploitability

The CVSS score is not supplied, but the EPSS score is <1%, indicating that exploitation is considered unlikely at present. Because the leak occurs via sysfs, the attack requires local user access and only reads kernel memory; elevated privileges are not needed. The vulnerability is not listed in the CISA KEV catalog, and no public exploit has been identified, so the overall risk is low to moderate for a local user but could be significant if an attacker can gain local access.

Generated by OpenCVE AI on September 18, 2026 at 08:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the kernel to a version where the qla2xxx mailbox struct is zeroed.
  • If an upgrade is not immediately possible, unload the qla2xxx module and disable its sysfs interfaces to prevent the information leak.
  • Restrict permissions on the relevant sysfs entries so that only privileged users can read them.

Generated by OpenCVE AI on September 18, 2026 at 08:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-457

Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Zero mailbox struct in qla2x00_get_firmware_state() The mbx_cmd_t is allocated on the stack but left uninitialized. qla2x00_mailbox_command() has several early-return paths (PCI permanent failure, device failed, EEH busy, ISP abort pending, mailbox access timeout, purge mbox) that return without writing the input mailbox registers back into mcp->mb[]. qla2x00_get_firmware_state() then unconditionally copies mcp->mb[1..6] (and mb[12]) into the caller's states[] array regardless of the return value. On such a failure the copied values are uninitialized kernel stack memory, which is then exposed to userspace via the fw_state and mpi_fw_state sysfs handlers. Zero the mailbox struct so a failed query yields deterministic zeroed state instead of leaking stack contents.
Title scsi: qla2xxx: Zero mailbox struct in qla2x00_get_firmware_state()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T10:31:26.012Z

Reserved: 2026-09-11T19:38:34.770Z

Link: CVE-2026-89852

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:16:52.900

Modified: 2026-09-16T11:16:52.900

Link: CVE-2026-89852

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T08:30:06Z

Weaknesses
  • CWE-457

    Use of Uninitialized Variable