CVE-2026-89458

Summary

In the Linux kernel, the following vulnerability has been resolved:

s390/dasd: Do not complete a failed ESE read as successful

dasd_int_handler() completes an NRF read of an unallocated ESE track by calling ese_read() and unconditionally marking the request DASD_CQR_SUCCESS. dasd_eckd_ese_read() can return an error before it has zeroed the destination buffer: a failed sense-data parse or a current track outside the requested range both return early, leaving the destination pages untouched. The request is still completed successfully, so the block layer is handed stale / uninitialized memory instead of zeros.

Check the ese_read() return value and fail the request through the normal error path instead of forcing DASD_CQR_SUCCESS.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux5e6bdd37c5526ef01326df5dabb93011ee89237e < c9adf8399732306dfc97b3adb4778038743e3f5eaffected
LinuxLinux5e6bdd37c5526ef01326df5dabb93011ee89237e < 52b331c99baac653ca794bd8487c8ec4de8db203affected
LinuxLinux5e6bdd37c5526ef01326df5dabb93011ee89237e < b0d94dd6e82df396e2254c8b0f25eff7d19c2e7faffected
LinuxLinux5e6bdd37c5526ef01326df5dabb93011ee89237e < cddb447c62466f3076938ce120028d7b591f9f37affected
LinuxLinuxfbbacd0dcbc3ae9398c569dbea96ae4b5ad97e04affected
LinuxLinux5f7c9989f11305aaa43e0f4378f4f070022a9f2baffected
LinuxLinux5.4.26 < 5.5affected
LinuxLinux5.5.10 < 5.6affected
LinuxLinux5.6affected
LinuxLinux0 < 5.6unaffected
LinuxLinux6.12.109 <= 6.12.*unaffected
LinuxLinux6.18.50 <= 6.18.*unaffected
LinuxLinux7.2.4 <= 7.2.*unaffected
LinuxLinux7.3-rc1 <= *unaffected

Weaknesses

References