{"api_version":"1","generated_at":"2026-09-16T16:40:20+00:00","cve":"CVE-2026-89849","urls":{"html":"https://cve.report/CVE-2026-89849","api":"https://cve.report/api/cve/CVE-2026-89849.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-89849","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-89849"},"summary":{"title":"scsi: qla2xxx: Reject non-SCSI SRB on status IOCB fast path","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: qla2xxx: Reject non-SCSI SRB on status IOCB fast path\n\nqla2x00_status_entry() filters out non-TYPE_SRB entries and the\nSRB_NVME_CMD, SRB_BIDI_CMD and SRB_TM_CMD types, then falls through to a\nSCSI fast path that assumes the command is an SRB_SCSI_CMD. The first\nthing on that path, qla_chk_edif_rx_sa_delete_pending(), and the\nsubsequent handling both evaluate GET_CMD_SP(sp), i.e. sp->u.scmd.cmd.\n\nThe srb u union overlays the SCSI command pointer with other command\nlayouts (bsg_job, iocb_cmd). If firmware delivers an unexpected\nSTATUS_TYPE IOCB for a non-SCSI handle, sp->u.scmd.cmd can read as a\nnon-NULL garbage pointer, bypassing the NULL checks in\nqla_chk_edif_rx_sa_delete_pending() and at the cp == NULL test, and\nleading to a wild pointer dereference.\n\nReject any SRB whose type is not SRB_SCSI_CMD before entering the fast\npath. The outstanding_cmds slot is left untouched so a genuinely\nnon-SCSI command still completes through its proper handler.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-09-16 11:16:52","updated_at":"2026-09-16 15:18:13"},"problem_types":[],"metrics":[{"version":"3.1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","score":"8.8","severity":"HIGH","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"8.8","severity":"HIGH","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","data":{"baseScore":8.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}}],"references":[{"url":"https://git.kernel.org/stable/c/9204fb0888374083be74f799049649a17eab4191","name":"https://git.kernel.org/stable/c/9204fb0888374083be74f799049649a17eab4191","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/8f0e31e7a41376abe7d6ca7cbee07fcf9de071e6","name":"https://git.kernel.org/stable/c/8f0e31e7a41376abe7d6ca7cbee07fcf9de071e6","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/b7418198b45b327194b97f856fe8ea8daa91f3fd","name":"https://git.kernel.org/stable/c/b7418198b45b327194b97f856fe8ea8daa91f3fd","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/e93aa3c5125d9a4352ac0fa8ba4a7f8f87881805","name":"https://git.kernel.org/stable/c/e93aa3c5125d9a4352ac0fa8ba4a7f8f87881805","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/0f41d07d72f2245208c45374ca8d0a1846cad667","name":"https://git.kernel.org/stable/c/0f41d07d72f2245208c45374ca8d0a1846cad667","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/29f1f9ad9e354cd0b6e4f6fc75ba09162d6a04d9","name":"https://git.kernel.org/stable/c/29f1f9ad9e354cd0b6e4f6fc75ba09162d6a04d9","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/e38041b47c29316ba79b645e2ae0b713d216b1db","name":"https://git.kernel.org/stable/c/e38041b47c29316ba79b645e2ae0b713d216b1db","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-89849","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89849","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected dd30706e73b70d67e88fdaca688db7a3374fd5de 9204fb0888374083be74f799049649a17eab4191 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected dd30706e73b70d67e88fdaca688db7a3374fd5de b7418198b45b327194b97f856fe8ea8daa91f3fd git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected dd30706e73b70d67e88fdaca688db7a3374fd5de 8f0e31e7a41376abe7d6ca7cbee07fcf9de071e6 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected dd30706e73b70d67e88fdaca688db7a3374fd5de e38041b47c29316ba79b645e2ae0b713d216b1db git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected dd30706e73b70d67e88fdaca688db7a3374fd5de e93aa3c5125d9a4352ac0fa8ba4a7f8f87881805 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected dd30706e73b70d67e88fdaca688db7a3374fd5de 29f1f9ad9e354cd0b6e4f6fc75ba09162d6a04d9 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected dd30706e73b70d67e88fdaca688db7a3374fd5de 0f41d07d72f2245208c45374ca8d0a1846cad667 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 5.15","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 5.15 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 5.15.221 5.15.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.1.188 6.1.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.6.157 6.6.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.12.110 6.12.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.51 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2.5 7.2.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.3-rc1 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["drivers/scsi/qla2xxx/qla_dbg.c","drivers/scsi/qla2xxx/qla_isr.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"9204fb0888374083be74f799049649a17eab4191","status":"affected","version":"dd30706e73b70d67e88fdaca688db7a3374fd5de","versionType":"git"},{"lessThan":"b7418198b45b327194b97f856fe8ea8daa91f3fd","status":"affected","version":"dd30706e73b70d67e88fdaca688db7a3374fd5de","versionType":"git"},{"lessThan":"8f0e31e7a41376abe7d6ca7cbee07fcf9de071e6","status":"affected","version":"dd30706e73b70d67e88fdaca688db7a3374fd5de","versionType":"git"},{"lessThan":"e38041b47c29316ba79b645e2ae0b713d216b1db","status":"affected","version":"dd30706e73b70d67e88fdaca688db7a3374fd5de","versionType":"git"},{"lessThan":"e93aa3c5125d9a4352ac0fa8ba4a7f8f87881805","status":"affected","version":"dd30706e73b70d67e88fdaca688db7a3374fd5de","versionType":"git"},{"lessThan":"29f1f9ad9e354cd0b6e4f6fc75ba09162d6a04d9","status":"affected","version":"dd30706e73b70d67e88fdaca688db7a3374fd5de","versionType":"git"},{"lessThan":"0f41d07d72f2245208c45374ca8d0a1846cad667","status":"affected","version":"dd30706e73b70d67e88fdaca688db7a3374fd5de","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["drivers/scsi/qla2xxx/qla_dbg.c","drivers/scsi/qla2xxx/qla_isr.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"5.15"},{"lessThan":"5.15","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"5.15.*","status":"unaffected","version":"5.15.221","versionType":"semver"},{"lessThanOrEqual":"6.1.*","status":"unaffected","version":"6.1.188","versionType":"semver"},{"lessThanOrEqual":"6.6.*","status":"unaffected","version":"6.6.157","versionType":"semver"},{"lessThanOrEqual":"6.12.*","status":"unaffected","version":"6.12.110","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.51","versionType":"semver"},{"lessThanOrEqual":"7.2.*","status":"unaffected","version":"7.2.5","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.3-rc1","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"5.15.221","versionStartIncluding":"5.15","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.1.188","versionStartIncluding":"5.15","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.6.157","versionStartIncluding":"5.15","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.12.110","versionStartIncluding":"5.15","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.51","versionStartIncluding":"5.15","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2.5","versionStartIncluding":"5.15","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.3-rc1","versionStartIncluding":"5.15","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: qla2xxx: Reject non-SCSI SRB on status IOCB fast path\n\nqla2x00_status_entry() filters out non-TYPE_SRB entries and the\nSRB_NVME_CMD, SRB_BIDI_CMD and SRB_TM_CMD types, then falls through to a\nSCSI fast path that assumes the command is an SRB_SCSI_CMD. The first\nthing on that path, qla_chk_edif_rx_sa_delete_pending(), and the\nsubsequent handling both evaluate GET_CMD_SP(sp), i.e. sp->u.scmd.cmd.\n\nThe srb u union overlays the SCSI command pointer with other command\nlayouts (bsg_job, iocb_cmd). If firmware delivers an unexpected\nSTATUS_TYPE IOCB for a non-SCSI handle, sp->u.scmd.cmd can read as a\nnon-NULL garbage pointer, bypassing the NULL checks in\nqla_chk_edif_rx_sa_delete_pending() and at the cp == NULL test, and\nleading to a wild pointer dereference.\n\nReject any SRB whose type is not SRB_SCSI_CMD before entering the fast\npath. The outstanding_cmds slot is left untouched so a genuinely\nnon-SCSI command still completes through its proper handler."}],"metrics":[{"cvssV3_1":{"baseScore":8.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"scenarios":[{"lang":"en","value":"AV:A - qla2xxx processes STATUS_TYPE IOCBs from the Fibre Channel/FCoE HBA response queue in interrupt context. A peer on the same SAN fabric can keep non-SCSI SRBs (login, CT, NACK, NVMe LS) outstanding and drive firmware completions; FC is a non-routable fabric, so Adjacent is the highest defensible vector.\nAC:L - Firmware already completes several non-SCSI types (NVMe, bidirectional, task-management) via STATUS_TYPE, and the SCSI fast path was an unguarded fall-through. Once a STATUS_TYPE IOCB names a non-SCSI handle, the type confusion is deterministic, with no race or layout outside attacker influence.\nPR:N - Fibre Channel has no host authentication by default. Fabric login, nameserver CT, target-mode NACK, and I/O completions are handled in the HBA ISR/DPC with no Linux account or capability required on the victim.\nUI:N - Response-queue processing runs automatically from the HBA interrupt and qla_do_work paths. No victim mount, open, or other user action is required.\nS:U - The type confusion and wild-pointer access occur in the host kernel that owns the qla2xxx driver. This is not a VM escape, IOMMU bypass, or other cross-authority impact.\nC:H - GET_CMD_SP(sp) overlays scsi_cmnd* with other SRB union members (bsg_job*, ctarg.iocb, ntfy, sa_ctl). Treating those live kernel pointers as scsi_cmnd yields wild reads of command and sense fields, a type-confusion primitive that can be leveraged for kernel memory disclosure.\nI:H - The same type confusion writes through the forged scsi_cmnd via scsi_set_resid and memset/memcpy of firmware sense data into cp->sense_buffer. Type confusion with those kernel writes is High integrity and can hijack control flow.\nA:H - Dereferencing the overlaid non-SCSI pointer as scsi_cmnd in interrupt/completion context causes a kernel oops or panic, matching related qla_chk_edif_rx_sa_delete_pending crashes on this path."}]}],"providerMetadata":{"dateUpdated":"2026-09-16T14:39:18.117Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/9204fb0888374083be74f799049649a17eab4191"},{"url":"https://git.kernel.org/stable/c/b7418198b45b327194b97f856fe8ea8daa91f3fd"},{"url":"https://git.kernel.org/stable/c/8f0e31e7a41376abe7d6ca7cbee07fcf9de071e6"},{"url":"https://git.kernel.org/stable/c/e38041b47c29316ba79b645e2ae0b713d216b1db"},{"url":"https://git.kernel.org/stable/c/e93aa3c5125d9a4352ac0fa8ba4a7f8f87881805"},{"url":"https://git.kernel.org/stable/c/29f1f9ad9e354cd0b6e4f6fc75ba09162d6a04d9"},{"url":"https://git.kernel.org/stable/c/0f41d07d72f2245208c45374ca8d0a1846cad667"}],"title":"scsi: qla2xxx: Reject non-SCSI SRB on status IOCB fast path","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-89849","datePublished":"2026-09-16T10:31:23.180Z","dateReserved":"2026-09-11T19:38:34.770Z","dateUpdated":"2026-09-16T14:39:18.117Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-16 11:16:52","lastModifiedDate":"2026-09-16 15:18:13","problem_types":[],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"89849","Ordinal":"1","Title":"scsi: qla2xxx: Reject non-SCSI SRB on status IOCB fast path","CVE":"CVE-2026-89849","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"89849","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: qla2xxx: Reject non-SCSI SRB on status IOCB fast path\n\nqla2x00_status_entry() filters out non-TYPE_SRB entries and the\nSRB_NVME_CMD, SRB_BIDI_CMD and SRB_TM_CMD types, then falls through to a\nSCSI fast path that assumes the command is an SRB_SCSI_CMD. The first\nthing on that path, qla_chk_edif_rx_sa_delete_pending(), and the\nsubsequent handling both evaluate GET_CMD_SP(sp), i.e. sp->u.scmd.cmd.\n\nThe srb u union overlays the SCSI command pointer with other command\nlayouts (bsg_job, iocb_cmd). If firmware delivers an unexpected\nSTATUS_TYPE IOCB for a non-SCSI handle, sp->u.scmd.cmd can read as a\nnon-NULL garbage pointer, bypassing the NULL checks in\nqla_chk_edif_rx_sa_delete_pending() and at the cp == NULL test, and\nleading to a wild pointer dereference.\n\nReject any SRB whose type is not SRB_SCSI_CMD before entering the fast\npath. The outstanding_cmds slot is left untouched so a genuinely\nnon-SCSI command still completes through its proper handler.","Type":"Description","Title":"scsi: qla2xxx: Reject non-SCSI SRB on status IOCB fast path"}]}}}