8.2
CVE-2026-89586
- EPSS 0.55%
- Veröffentlicht 11.09.2026 19:44:51
- Zuletzt bearbeitet 14.09.2026 13:19:12
- Erkennungen
ata: libata-scsi: fix DSM TRIM for sector sizes larger than 2048 bytes
In the Linux kernel, the following vulnerability has been resolved: ata: libata-scsi: fix DSM TRIM for sector sizes larger than 2048 bytes ata_scsi_write_same_xlat() translates a SCSI WRITE SAME command with the UNMAP bit set into an ATA DATA SET MANAGEMENT TRIM command. The TRIM descriptor is built by ata_format_dsm_trim_descr() into the 2048-byte ata_scsi_rbuf staging buffer, and the number of bytes copied is compared against the logical sector size by the caller: size = ata_format_dsm_trim_descr(scmd, trmax, block, n_block); if (size != len) /* len == sdp->sector_size */ goto invalid_param_len; ata_format_dsm_trim_descr() clamps the copy length to ATA_SCSI_RBUF_SIZE (2048). On a device whose logical sector size exceeds that (e.g. a 4Kn device, where sector_size == 4096) the function can never return more than 2048, while the caller expects it to return sector_size. The comparison therefore always fails, so every TRIM is rejected with "Parameter list length error" and WARN_ON() splats on each attempt. TRIM / discard is thus completely broken on such devices. The descriptor was incorrectly sized from the logical sector size. A DSM TRIM payload is a list of 512-byte pages, each holding up to ATA_MAX_TRIM_RNUM (64) LBA Range Entries, and is independent of the logical sector size. The Block Limits VPD page already advertises a single such page as the maximum WRITE SAME length (65535 * ATA_MAX_TRIM_RNUM logical blocks), so the block layer never sends a request that needs more than one page. Emit exactly one 512-byte page, independent of the logical sector size, and transfer only that page (COUNT == 1). For a 512-byte-sector device this is unchanged; devices with larger logical sectors now work instead of failing every TRIM.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
ef2d7392c4ece5c3cd12a6c7ca9366cd8f189aff
Version <
07975b8daa3b0ab3cbc02cc48ea7bc48fadcec53
Status
affected
Version
ef2d7392c4ece5c3cd12a6c7ca9366cd8f189aff
Version <
b7b5ab2df325ffbbad7ca2debaa071e024d68cb5
Status
affected
Version
ef2d7392c4ece5c3cd12a6c7ca9366cd8f189aff
Version <
07baa310ea3224a7044b1ca84796bb37a235af1f
Status
affected
Version
ef2d7392c4ece5c3cd12a6c7ca9366cd8f189aff
Version <
977554ed91b54075fbc0bac536316b4841ef6258
Status
affected
Version
ef2d7392c4ece5c3cd12a6c7ca9366cd8f189aff
Version <
04e2befe25792f2e90097f284d7e86fc6bcfe928
Status
affected
Version
ef2d7392c4ece5c3cd12a6c7ca9366cd8f189aff
Version <
c2e3dccd6870659851eaa4c12ab16418b8e3040a
Status
affected
Version
ef2d7392c4ece5c3cd12a6c7ca9366cd8f189aff
Version <
4a4268a0b0a595bd9534cf9c7fda93775a7d8a0d
Status
affected
Version
ef2d7392c4ece5c3cd12a6c7ca9366cd8f189aff
Version <
79cce911e623c0baa0fde307ce3a434e084b881a
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
4.9
Status
affected
Version
0
Version <
4.9
Status
unaffected
Version <=
5.10.*
Version
5.10.270
Status
unaffected
Version <=
5.15.*
Version
5.15.221
Status
unaffected
Version <=
6.1.*
Version
6.1.188
Status
unaffected
Version <=
6.6.*
Version
6.6.157
Status
unaffected
Version <=
6.12.*
Version
6.12.109
Status
unaffected
Version <=
6.18.*
Version
6.18.50
Status
unaffected
Version <=
7.2.*
Version
7.2.4
Status
unaffected
Version <=
*
Version
7.3-rc1
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.55% | 0.441 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | 8.2 | 3.9 | 4.2 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
|
https://git.kernel.org/stable/c/04e2befe25792f2e90097f284d7e86fc6bcfe928
https://git.kernel.org/stable/c/c2e3dccd6870659851eaa4c12ab16418b8e3040a
https://git.kernel.org/stable/c/4a4268a0b0a595bd9534cf9c7fda93775a7d8a0d
https://git.kernel.org/stable/c/79cce911e623c0baa0fde307ce3a434e084b881a
https://git.kernel.org/stable/c/07975b8daa3b0ab3cbc02cc48ea7bc48fadcec53
https://git.kernel.org/stable/c/07baa310ea3224a7044b1ca84796bb37a235af1f
https://git.kernel.org/stable/c/977554ed91b54075fbc0bac536316b4841ef6258
https://git.kernel.org/stable/c/b7b5ab2df325ffbbad7ca2debaa071e024d68cb5