๐Ÿ” CVE Alert

CVE-2026-89864

UNKNOWN 0.0

scsi: qla2xxx: Bound i2c->length in I2C bsg handlers

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Bound i2c->length in I2C bsg handlers struct qla_i2c_access carries a 16-bit length field alongside a fixed 64-byte buffer: struct qla_i2c_access { uint16_t device, offset, option, length; uint8_t buffer[0x40]; } __packed; qla2x00_write_i2c() and qla2x00_read_i2c() use the user-supplied i2c->length without any bounds check. i2c is overlaid on a 256-byte on-stack buffer and sfp is a 256-byte DMA-pool buffer, so a length up to 65535 overruns both: - write: memcpy(sfp, i2c->buffer, i2c->length) over-reads the stack and over-writes the sfp heap buffer, and qla2x00_write_sfp() then DMAs i2c->length bytes out of the 256-byte buffer. - read: qla2x00_read_sfp() DMAs i2c->length bytes into the 256-byte sfp, then memcpy(i2c->buffer, sfp, i2c->length) overflows the 64-byte buffer inside the on-stack array. A caller holding CAP_SYS_RAWIO can use this to corrupt the heap and the kernel stack. Reject requests whose length exceeds the buffer before any copy or DMA transfer in both handlers.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 16, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
9ebb5d9c69f1f5721f9f6f49e501c674c1e184ae < 8f01f886cc5e7bbc16cbf1a9928fdebbc911e973 9ebb5d9c69f1f5721f9f6f49e501c674c1e184ae < 2be39946abcde5a6416fb074ef728429e246a996 9ebb5d9c69f1f5721f9f6f49e501c674c1e184ae < 522d6dcdc645d8f97d6b4cdfd6d8eea307f3ff0e 9ebb5d9c69f1f5721f9f6f49e501c674c1e184ae < 9a756f277eb89f769dbf380f38245c270d31fdb5 9ebb5d9c69f1f5721f9f6f49e501c674c1e184ae < 32d6df14fdab71fe1ba304fd9a0db0411ea2e043 9ebb5d9c69f1f5721f9f6f49e501c674c1e184ae < 97ca58b0fb026799b99e3d552d5f69cf9a3113ad 9ebb5d9c69f1f5721f9f6f49e501c674c1e184ae < 47049fdadc0eaa115e813735b827e1379c0d2cf8 9ebb5d9c69f1f5721f9f6f49e501c674c1e184ae < 0918ee2c0eeb4d7f45b82b3dc11e65c2d9b7ad59
Linux / Linux
3.7

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/8f01f886cc5e7bbc16cbf1a9928fdebbc911e973 git.kernel.org: https://git.kernel.org/stable/c/2be39946abcde5a6416fb074ef728429e246a996 git.kernel.org: https://git.kernel.org/stable/c/522d6dcdc645d8f97d6b4cdfd6d8eea307f3ff0e git.kernel.org: https://git.kernel.org/stable/c/9a756f277eb89f769dbf380f38245c270d31fdb5 git.kernel.org: https://git.kernel.org/stable/c/32d6df14fdab71fe1ba304fd9a0db0411ea2e043 git.kernel.org: https://git.kernel.org/stable/c/97ca58b0fb026799b99e3d552d5f69cf9a3113ad git.kernel.org: https://git.kernel.org/stable/c/47049fdadc0eaa115e813735b827e1379c0d2cf8 git.kernel.org: https://git.kernel.org/stable/c/0918ee2c0eeb4d7f45b82b3dc11e65c2d9b7ad59