Description
In the Linux kernel, the following vulnerability has been resolved:

scsi: qla2xxx: Zero SFP DMA buffer in FRU/I2C bsg handlers

The FRU and I2C bsg handlers stage their transfer in a DMA_POOL_SIZE
(256-byte) bounce buffer obtained from dma_pool_alloc(), which does not
zero the allocation. They initialize only a few leading bytes before
handing the buffer to qla2x00_write_sfp().

qla2x00_write_sfp() can override the transfer length with a user-supplied
value:

if (len == 1)
opt |= BIT_0;
if (opt & BIT_0)
len = *sfp;

*sfp is the first byte of the (user-controlled) payload, so len can grow
up to 255. The device then DMA-reads len bytes from the 256-byte pool
buffer. Since only a small prefix was written
(e.g. MAX_FRU_SIZE == 36 bytes for a FRU version, one byte for a FRU
status register), the hardware reads past the initialized region and
writes up to ~219 bytes of stale DMA-pool heap memory to the device
flash.

Allocate the buffer with dma_pool_zalloc() in all five FRU/I2C handlers
so any bytes beyond the initialized data are zero rather than stale heap
contents.
Published: 2026-09-16
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Integrity Compromise – device flash corrupted
Action: Patch Immediately
AI Analysis

Impact

The kernel’s qla2xxx SCSI driver allocates a 256‑byte DMA bounce buffer using dma_pool_alloc(), which does not clear the memory. The driver only writes the first few bytes before passing the buffer to qla2x00_write_sfp(), where a user‑controlled length field can be overridden to read up to 255 bytes from the buffer. Because the remaining bytes are uninitialised, the device performs a DMA read of the full length, causing stale memory contents to be written to the device’s flash storage. This flaw can corrupt firmware or other persistent data on the device, potentially leading to loss of integrity and application failure. The weakness involves improper initialization and a form of heap‑based buffer misuse, corresponding to CWE‑122 and CWE‑665.

Affected Systems

Any Linux kernel that includes the qla2xxx driver before the patch that replaces dma_pool_alloc() with dma_pool_zalloc() in the FRU/I2C bsg handlers is affected. The specific kernel releases are not listed in the advisory, so all builds using the vulnerable code path are considered at risk.

Risk and Exploitability

Because the exploit requires the attacker to supply a specially crafted SFP payload that is transmitted to the device, the attack vector is local to the environment that controls the SCSI I/O. The EPSS score of <1% indicates a very low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, the impact on device integrity is high, as corrupted flash may render the device unusable. The CVSS score is not provided, but the vulnerability’s potential to permanently alter stored data suggests a high severity if an attacker succeeds.

Generated by OpenCVE AI on September 18, 2026 at 08:19 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the kernel to a release that applies the patch replacing dma_pool_alloc with dma_pool_zalloc in the qla2xxx driver.
  • If an immediate kernel update is not feasible, manually replace the allocation calls in the driver source with dma_pool_zalloc and rebuild the kernel for the affected system.
  • After applying the fix, verify the device firmware integrity and consider reflashing the device’s flash to recover from any potential corruption.

Generated by OpenCVE AI on September 18, 2026 at 08:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Zero SFP DMA buffer in FRU/I2C bsg handlers The FRU and I2C bsg handlers stage their transfer in a DMA_POOL_SIZE (256-byte) bounce buffer obtained from dma_pool_alloc(), which does not zero the allocation. They initialize only a few leading bytes before handing the buffer to qla2x00_write_sfp(). qla2x00_write_sfp() can override the transfer length with a user-supplied value: if (len == 1) opt |= BIT_0; if (opt & BIT_0) len = *sfp; *sfp is the first byte of the (user-controlled) payload, so len can grow up to 255. The device then DMA-reads len bytes from the 256-byte pool buffer. Since only a small prefix was written (e.g. MAX_FRU_SIZE == 36 bytes for a FRU version, one byte for a FRU status register), the hardware reads past the initialized region and writes up to ~219 bytes of stale DMA-pool heap memory to the device flash. Allocate the buffer with dma_pool_zalloc() in all five FRU/I2C handlers so any bytes beyond the initialized data are zero rather than stale heap contents.
Title scsi: qla2xxx: Zero SFP DMA buffer in FRU/I2C bsg handlers
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T10:31:35.758Z

Reserved: 2026-09-11T19:38:34.771Z

Link: CVE-2026-89865

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:16:54.610

Modified: 2026-09-16T11:16:54.610

Link: CVE-2026-89865

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T09:00:08Z

Weaknesses

No weakness.