-
CVE-2026-89864
- EPSS 0.21%
- Veröffentlicht 16.09.2026 10:31:35
- Zuletzt bearbeitet 16.09.2026 11:16:54
- Erkennungen
scsi: qla2xxx: Bound i2c->length in I2C bsg handlers
In the Linux kernel, the following vulnerability has been resolved:
scsi: qla2xxx: Bound i2c->length in I2C bsg handlers
struct qla_i2c_access carries a 16-bit length field alongside a fixed
64-byte buffer:
struct qla_i2c_access {
uint16_t device, offset, option, length;
uint8_t buffer[0x40];
} __packed;
qla2x00_write_i2c() and qla2x00_read_i2c() use the user-supplied
i2c->length without any bounds check. i2c is overlaid on a 256-byte
on-stack buffer and sfp is a 256-byte DMA-pool buffer, so a length up to
65535 overruns both:
- write: memcpy(sfp, i2c->buffer, i2c->length) over-reads the stack and
over-writes the sfp heap buffer, and qla2x00_write_sfp() then DMAs
i2c->length bytes out of the 256-byte buffer.
- read: qla2x00_read_sfp() DMAs i2c->length bytes into the 256-byte sfp,
then memcpy(i2c->buffer, sfp, i2c->length) overflows the 64-byte
buffer inside the on-stack array.
A caller holding CAP_SYS_RAWIO can use this to corrupt the heap and the
kernel stack. Reject requests whose length exceeds the buffer before any
copy or DMA transfer in both handlers.Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
9ebb5d9c69f1f5721f9f6f49e501c674c1e184ae
Version <
8f01f886cc5e7bbc16cbf1a9928fdebbc911e973
Status
affected
Version
9ebb5d9c69f1f5721f9f6f49e501c674c1e184ae
Version <
2be39946abcde5a6416fb074ef728429e246a996
Status
affected
Version
9ebb5d9c69f1f5721f9f6f49e501c674c1e184ae
Version <
522d6dcdc645d8f97d6b4cdfd6d8eea307f3ff0e
Status
affected
Version
9ebb5d9c69f1f5721f9f6f49e501c674c1e184ae
Version <
9a756f277eb89f769dbf380f38245c270d31fdb5
Status
affected
Version
9ebb5d9c69f1f5721f9f6f49e501c674c1e184ae
Version <
32d6df14fdab71fe1ba304fd9a0db0411ea2e043
Status
affected
Version
9ebb5d9c69f1f5721f9f6f49e501c674c1e184ae
Version <
97ca58b0fb026799b99e3d552d5f69cf9a3113ad
Status
affected
Version
9ebb5d9c69f1f5721f9f6f49e501c674c1e184ae
Version <
47049fdadc0eaa115e813735b827e1379c0d2cf8
Status
affected
Version
9ebb5d9c69f1f5721f9f6f49e501c674c1e184ae
Version <
0918ee2c0eeb4d7f45b82b3dc11e65c2d9b7ad59
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
3.7
Status
affected
Version
0
Version <
3.7
Status
unaffected
Version <=
5.10.*
Version
5.10.270
Status
unaffected
Version <=
5.15.*
Version
5.15.221
Status
unaffected
Version <=
6.1.*
Version
6.1.188
Status
unaffected
Version <=
6.6.*
Version
6.6.157
Status
unaffected
Version <=
6.12.*
Version
6.12.110
Status
unaffected
Version <=
6.18.*
Version
6.18.51
Status
unaffected
Version <=
7.2.*
Version
7.2.5
Status
unaffected
Version <=
*
Version
7.3-rc1
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.21% | 0.116 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|
https://git.kernel.org/stable/c/8f01f886cc5e7bbc16cbf1a9928fdebbc911e973
https://git.kernel.org/stable/c/2be39946abcde5a6416fb074ef728429e246a996
https://git.kernel.org/stable/c/522d6dcdc645d8f97d6b4cdfd6d8eea307f3ff0e
https://git.kernel.org/stable/c/9a756f277eb89f769dbf380f38245c270d31fdb5
https://git.kernel.org/stable/c/32d6df14fdab71fe1ba304fd9a0db0411ea2e043
https://git.kernel.org/stable/c/97ca58b0fb026799b99e3d552d5f69cf9a3113ad
https://git.kernel.org/stable/c/47049fdadc0eaa115e813735b827e1379c0d2cf8
https://git.kernel.org/stable/c/0918ee2c0eeb4d7f45b82b3dc11e65c2d9b7ad59