Description
In the Linux kernel, the following vulnerability has been resolved:

scsi: qla2xxx: Bound i2c->length in I2C bsg handlers

struct qla_i2c_access carries a 16-bit length field alongside a fixed
64-byte buffer:

struct qla_i2c_access {
uint16_t device, offset, option, length;
uint8_t buffer[0x40];
} __packed;

qla2x00_write_i2c() and qla2x00_read_i2c() use the user-supplied
i2c->length without any bounds check. i2c is overlaid on a 256-byte
on-stack buffer and sfp is a 256-byte DMA-pool buffer, so a length up to
65535 overruns both:

- write: memcpy(sfp, i2c->buffer, i2c->length) over-reads the stack and
over-writes the sfp heap buffer, and qla2x00_write_sfp() then DMAs
i2c->length bytes out of the 256-byte buffer.
- read: qla2x00_read_sfp() DMAs i2c->length bytes into the 256-byte sfp,
then memcpy(i2c->buffer, sfp, i2c->length) overflows the 64-byte
buffer inside the on-stack array.

A caller holding CAP_SYS_RAWIO can use this to corrupt the heap and the
kernel stack. Reject requests whose length exceeds the buffer before any
copy or DMA transfer in both handlers.
Published: 2026-09-16
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Kernel memory corruption potentially enabling privilege escalation
Action: Apply patch
AI Analysis

Impact

In the Linux kernel the qla2xxx SCSI driver exposes an unchecked i2c->length field in its BSG handlers. The driver copies or DMA‑transfers the specified length without bounding it against the fixed 64‑byte buffer. When the length exceeds the buffer, the write path over‑reads the stack and overwrites heap memory, and the read path overflows the stack buffer and later copies the overrun data to the kernel. An attacker with CAP_SYS_RAWIO can trigger these overflows to corrupt kernel data structures, enabling an elevation of privilege or remote code execution.

Affected Systems

All Linux kernel builds prior to the commit that introduced the bounds‑check are affected. The vulnerability exists in the qla2xxx SCSI driver regardless of platform, so any system running an unpatched kernel that includes this driver is at risk. No specific vendor version enumeration is supplied, but the patch is linked in the provided references and applies to all kernels before the fix.

Risk and Exploitability

The EPSS score is less than 1% and the vulnerability is not listed in the CISA KEV catalog, indicating a low likelihood of widespread exploitation. However, the flaw requires CAP_SYS_RAWIO, so only processes or users with raw I/O capability can exercise it. Because a kernel memory corruption can have catastrophic consequences, the overall severity is high for environments that grant raw I/O access, while systems that enforce strict capability restrictions face a lower risk.

Generated by OpenCVE AI on September 18, 2026 at 08:44 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the qla2xxx bounds check.
  • Restrict the CAP_SYS_RAWIO capability to trusted administrative processes only; consider using Linux capabilities or SELinux policies to limit its use.
  • Monitor kernel audit logs for BSG or I2C transfer attempts, and watch for abnormal memory access patterns or errors.

Generated by OpenCVE AI on September 18, 2026 at 08:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
CWE-120

Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Bound i2c->length in I2C bsg handlers struct qla_i2c_access carries a 16-bit length field alongside a fixed 64-byte buffer: struct qla_i2c_access { uint16_t device, offset, option, length; uint8_t buffer[0x40]; } __packed; qla2x00_write_i2c() and qla2x00_read_i2c() use the user-supplied i2c->length without any bounds check. i2c is overlaid on a 256-byte on-stack buffer and sfp is a 256-byte DMA-pool buffer, so a length up to 65535 overruns both: - write: memcpy(sfp, i2c->buffer, i2c->length) over-reads the stack and over-writes the sfp heap buffer, and qla2x00_write_sfp() then DMAs i2c->length bytes out of the 256-byte buffer. - read: qla2x00_read_sfp() DMAs i2c->length bytes into the 256-byte sfp, then memcpy(i2c->buffer, sfp, i2c->length) overflows the 64-byte buffer inside the on-stack array. A caller holding CAP_SYS_RAWIO can use this to corrupt the heap and the kernel stack. Reject requests whose length exceeds the buffer before any copy or DMA transfer in both handlers.
Title scsi: qla2xxx: Bound i2c->length in I2C bsg handlers
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T10:31:35.068Z

Reserved: 2026-09-11T19:38:34.771Z

Link: CVE-2026-89864

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:16:54.480

Modified: 2026-09-16T11:16:54.480

Link: CVE-2026-89864

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T15:15:16Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-120

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')