Description
In the Linux kernel, the following vulnerability has been resolved:

scsi: qla2xxx: Bound image count in qla2x00_update_fru_versions()

qla2x00_update_fru_versions() copies the user-supplied BSG request into
a fixed 256-byte stack buffer (bsg[DMA_POOL_SIZE]) and then iterates
list->count times over the qla_image_version array embedded in that
buffer, advancing the image pointer each iteration. count is taken
directly from user input with no upper bound, while only (DMA_POOL_SIZE
- sizeof(list->count)) / sizeof(struct qla_image_version) = 6 entries
actually fit. A larger count walks the image pointer off the end of the
stack buffer, reading adjacent kernel stack memory and sending it to the
device via qla2x00_write_sfp().

Reject requests whose declared count does not fit in the buffer.
Published: 2026-09-16
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Kernel memory disclosure via out‑of‑bounds read on qla2xxx SCSI driver
Action: Patch
AI Analysis

Impact

The flaw is in the Linux kernel qla2xxx SCSI driver; the function qla2x00_update_fru_versions() copies a user‑supplied BSG request into a fixed 256‑byte stack buffer without validating the count field. The count is taken directly from the user’s request, and the code then iterates that many times over the embedded qla_image_version array. Only six entries fit in the buffer; a larger count causes the pointer to read beyond the buffer’s bounds, leaking adjacent kernel stack memory to the device via qla2x00_write_sfp(). This out‑of‑bounds read can expose sensitive kernel data.

Affected Systems

Any Linux system that contains the unpatched qla2xxx driver is affected, regardless of architecture. The vulnerability exists in all kernel releases that include the legacy qla2xxx routine; the fix was introduced in later revisions with the boundary check and request rejection logic.

Risk and Exploitability

The EPSS score is less than 1% and the vulnerability is not listed in CISA KEV, indicating a low exploitation probability. Exploitation requires constructing a BSG request with an invalid count and sending it to the qla2xxx device file, which typically needs local or privileged access to that hardware interface. Successful exploitation results in memory disclosure from the kernel stack, which could assist in further privilege escalation or information gathering.

Generated by OpenCVE AI on October 1, 2026 at 21:40 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a Linux kernel update that incorporates the qla2xxx driver fix and boundary checks for the BSG request count field.
  • Restrict access to the /dev/sgX device files used by the qla2xxx driver, ensuring that only privileged users can issue BSG requests.
  • If the QLogic HBAs are not needed, blacklist or unload the qla2xxx kernel module to eliminate the attack surface.

Generated by OpenCVE AI on October 1, 2026 at 21:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Bound image count in qla2x00_update_fru_versions() qla2x00_update_fru_versions() copies the user-supplied BSG request into a fixed 256-byte stack buffer (bsg[DMA_POOL_SIZE]) and then iterates list->count times over the qla_image_version array embedded in that buffer, advancing the image pointer each iteration. count is taken directly from user input with no upper bound, while only (DMA_POOL_SIZE - sizeof(list->count)) / sizeof(struct qla_image_version) = 6 entries actually fit. A larger count walks the image pointer off the end of the stack buffer, reading adjacent kernel stack memory and sending it to the device via qla2x00_write_sfp(). Reject requests whose declared count does not fit in the buffer.
Title scsi: qla2xxx: Bound image count in qla2x00_update_fru_versions()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T10:31:30.876Z

Reserved: 2026-09-11T19:38:34.771Z

Link: CVE-2026-89858

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:16:53.693

Modified: 2026-09-16T11:16:53.693

Link: CVE-2026-89858

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T21:45:06Z

Weaknesses

No weakness.