scsi: qla2xxx: Zero SFP DMA buffer in FRU/I2C bsg handlers

Summary

CVECVE-2026-89865
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-09-16 11:16:54 UTC
Updated2026-09-16 11:16:54 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Zero SFP DMA buffer in FRU/I2C bsg handlers The FRU and I2C bsg handlers stage their transfer in a DMA_POOL_SIZE (256-byte) bounce buffer obtained from dma_pool_alloc(), which does not zero the allocation. They initialize only a few leading bytes before handing the buffer to qla2x00_write_sfp(). qla2x00_write_sfp() can override the transfer length with a user-supplied value: if (len == 1) opt |= BIT_0; if (opt & BIT_0) len = *sfp; *sfp is the first byte of the (user-controlled) payload, so len can grow up to 255. The device then DMA-reads len bytes from the 256-byte pool buffer. Since only a small prefix was written (e.g. MAX_FRU_SIZE == 36 bytes for a FRU version, one byte for a FRU status register), the hardware reads past the initialized region and writes up to ~219 bytes of stale DMA-pool heap memory to the device flash. Allocate the buffer with dma_pool_zalloc() in all five FRU/I2C handlers so any bytes beyond the initialized data are zero rather than stale heap contents.

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected 697a4bc69159c3396035b0506ffa55c4b2d0b1f4 a476377a66897549dd49bee319f4df66623417b7 git Not specified
CNA Linux Linux affected 697a4bc69159c3396035b0506ffa55c4b2d0b1f4 09703bc7c0be3a7a155b0ff5f21f6765ba3f519c git Not specified
CNA Linux Linux affected 697a4bc69159c3396035b0506ffa55c4b2d0b1f4 97c45c75f5cdec96b1a4fba8b1d55d0dd01af1e8 git Not specified
CNA Linux Linux affected 697a4bc69159c3396035b0506ffa55c4b2d0b1f4 84bde5ce4038d9ad811e5c994305bbfcbd7a9f79 git Not specified
CNA Linux Linux affected 697a4bc69159c3396035b0506ffa55c4b2d0b1f4 581590f560b74399151b3cbc88574424c2f3d2dc git Not specified
CNA Linux Linux affected 697a4bc69159c3396035b0506ffa55c4b2d0b1f4 b157256c28086c434afd70cc78bf9b4d8caf1276 git Not specified
CNA Linux Linux affected 697a4bc69159c3396035b0506ffa55c4b2d0b1f4 a5501c42256235523c4dddf799f032dfbf4f4c77 git Not specified
CNA Linux Linux affected 697a4bc69159c3396035b0506ffa55c4b2d0b1f4 b47d4a1547d9ef21b2e9d1a739fe2204d4be05dc git Not specified
CNA Linux Linux affected 3.2 Not specified
CNA Linux Linux unaffected 3.2 semver Not specified
CNA Linux Linux unaffected 5.10.270 5.10.* semver Not specified
CNA Linux Linux unaffected 5.15.221 5.15.* semver Not specified
CNA Linux Linux unaffected 6.1.188 6.1.* semver Not specified
CNA Linux Linux unaffected 6.6.157 6.6.* semver Not specified
CNA Linux Linux unaffected 6.12.110 6.12.* semver Not specified
CNA Linux Linux unaffected 6.18.51 6.18.* semver Not specified
CNA Linux Linux unaffected 7.2.5 7.2.* semver Not specified
CNA Linux Linux unaffected 7.3-rc1 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/84bde5ce4038d9ad811e5c994305bbfcbd7a9f79 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/a476377a66897549dd49bee319f4df66623417b7 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/09703bc7c0be3a7a155b0ff5f21f6765ba3f519c 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/b157256c28086c434afd70cc78bf9b4d8caf1276 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/a5501c42256235523c4dddf799f032dfbf4f4c77 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/581590f560b74399151b3cbc88574424c2f3d2dc 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/97c45c75f5cdec96b1a4fba8b1d55d0dd01af1e8 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/b47d4a1547d9ef21b2e9d1a739fe2204d4be05dc 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report