Description
In the Linux kernel, the following vulnerability has been resolved:

scsi: qla2xxx: Zero dport diagnostics buffer to avoid info leak

qla2x00_do_dport_diagnostics() allocates the qla_dport_diag response
buffer with kmalloc_obj() (non-zeroing) and, on success, copies the full
sizeof(*dd) back to user space via sg_copy_from_buffer(). The inbound
sg_copy_to_buffer() only fills as many bytes as the user request payload
provides, and qla26xx_dport_diagnostics() zeroes only dd->buf. The
options and unused[] fields are therefore copied out uninitialized,
leaking kernel heap contents to user space.

Allocate with kzalloc_obj(), matching qla2x00_do_dport_diagnostics_v2().
Published: 2026-09-16
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Immediate Patch
AI Analysis

Impact

The qla2xxx SCSI driver allocates a diagnostics buffer with kmalloc_obj, which does not zero memory. The driver then copies this buffer back to user space, but only the user‑requested portion is zeroed; the remaining fields retain whatever was on the kernel heap, leading to leakage of uninitialized kernel data. The vulnerability is an information‑exposure flaw that could expose sensitive memory contents to an unprivileged user.

Affected Systems

Any Linux system running a kernel that includes the qla2xxx driver before the safety fix commit. The vulnerability does not target a particular kernel version list, so all affected distributions using the unpatched driver are at risk until the kernel is updated.

Risk and Exploitability

The EPSS score of less than 1% indicates a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. An attacker would need local access to a QLogic SCSI device to trigger the diagnostic operation and read the exposed data. The impact is a confidentiality breach; integrity and availability are not directly affected by the attack vector described. The risk level remains low to moderate depending on the system’s exposure to local users who can issue SCSI commands.

Generated by OpenCVE AI on September 18, 2026 at 08:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes the patch for the qla2xxx driver; the fix uses kzalloc_obj to zero the buffer before copying.
  • If an update cannot be applied immediately, restrict or remove access to the QLogic SCSI devices from untrusted users, for example by adjusting device permissions or isolating the devices in a separate security context.
  • As a temporary measure, if you can modify the driver source, replace kmalloc_obj with kzalloc_obj or explicitly zero all fields of the diagnostics buffer before copying data back to user space.

Generated by OpenCVE AI on September 18, 2026 at 08:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 03 Oct 2026 11:15:00 +0000


Mon, 21 Sep 2026 13:30:00 +0000


Fri, 18 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-457

Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Zero dport diagnostics buffer to avoid info leak qla2x00_do_dport_diagnostics() allocates the qla_dport_diag response buffer with kmalloc_obj() (non-zeroing) and, on success, copies the full sizeof(*dd) back to user space via sg_copy_from_buffer(). The inbound sg_copy_to_buffer() only fills as many bytes as the user request payload provides, and qla26xx_dport_diagnostics() zeroes only dd->buf. The options and unused[] fields are therefore copied out uninitialized, leaking kernel heap contents to user space. Allocate with kzalloc_obj(), matching qla2x00_do_dport_diagnostics_v2().
Title scsi: qla2xxx: Zero dport diagnostics buffer to avoid info leak
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-10-03T10:56:49.159Z

Reserved: 2026-09-11T19:38:34.771Z

Link: CVE-2026-89859

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:16:53.830

Modified: 2026-10-03T11:17:44.560

Link: CVE-2026-89859

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T08:30:06Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-457

    Use of Uninitialized Variable