CVE-2026-89586

Summary

In the Linux kernel, the following vulnerability has been resolved:

ata: libata-scsi: fix DSM TRIM for sector sizes larger than 2048 bytes

ata_scsi_write_same_xlat() translates a SCSI WRITE SAME command with the UNMAP bit set into an ATA DATA SET MANAGEMENT TRIM command. The TRIM descriptor is built by ata_format_dsm_trim_descr() into the 2048-byte ata_scsi_rbuf staging buffer, and the number of bytes copied is compared against the logical sector size by the caller:

size = ata_format_dsm_trim_descr(scmd, trmax, block, n_block);
if (size != len)		/* len == sdp->sector_size */
	goto invalid_param_len;

ata_format_dsm_trim_descr() clamps the copy length to ATA_SCSI_RBUF_SIZE (2048). On a device whose logical sector size exceeds that (e.g. a 4Kn device, where sector_size == 4096) the function can never return more than 2048, while the caller expects it to return sector_size. The comparison therefore always fails, so every TRIM is rejected with "Parameter list length error" and WARN_ON() splats on each attempt. TRIM / discard is thus completely broken on such devices.

The descriptor was incorrectly sized from the logical sector size. A DSM TRIM payload is a list of 512-byte pages, each holding up to ATA_MAX_TRIM_RNUM (64) LBA Range Entries, and is independent of the logical sector size. The Block Limits VPD page already advertises a single such page as the maximum WRITE SAME length (65535 * ATA_MAX_TRIM_RNUM logical blocks), so the block layer never sends a request that needs more than one page.

Emit exactly one 512-byte page, independent of the logical sector size, and transfer only that page (COUNT == 1). For a 512-byte-sector device this is unchanged; devices with larger logical sectors now work instead of failing every TRIM.

Affected Software

VendorProductVersion RangeStatus
LinuxLinuxef2d7392c4ece5c3cd12a6c7ca9366cd8f189aff < 04e2befe25792f2e90097f284d7e86fc6bcfe928affected
LinuxLinuxef2d7392c4ece5c3cd12a6c7ca9366cd8f189aff < c2e3dccd6870659851eaa4c12ab16418b8e3040aaffected
LinuxLinuxef2d7392c4ece5c3cd12a6c7ca9366cd8f189aff < 4a4268a0b0a595bd9534cf9c7fda93775a7d8a0daffected
LinuxLinuxef2d7392c4ece5c3cd12a6c7ca9366cd8f189aff < 79cce911e623c0baa0fde307ce3a434e084b881aaffected
LinuxLinux4.9affected
LinuxLinux0 < 4.9unaffected
LinuxLinux6.12.109 <= 6.12.*unaffected
LinuxLinux6.18.50 <= 6.18.*unaffected
LinuxLinux7.2.4 <= 7.2.*unaffected
LinuxLinux7.3-rc1 <= *unaffected

Weaknesses

References