CVE-2026-89864
N/A
N/A
Summary
In the Linux kernel, the following vulnerability has been resolved:
scsi: qla2xxx: Bound i2c->length in I2C bsg handlers
struct qla_i2c_access carries a 16-bit length field alongside a fixed 64-byte buffer:
struct qla_i2c_access {
uint16_t device, offset, option, length;
uint8_t buffer[0x40];
} __packed;
qla2x00_write_i2c() and qla2x00_read_i2c() use the user-supplied i2c->length without any bounds check. i2c is overlaid on a 256-byte on-stack buffer and sfp is a 256-byte DMA-pool buffer, so a length up to 65535 overruns both:
- write: memcpy(sfp, i2c->buffer, i2c->length) over-reads the stack and over-writes the sfp heap buffer, and qla2x00_write_sfp() then DMAs i2c->length bytes out of the 256-byte buffer.
- read: qla2x00_read_sfp() DMAs i2c->length bytes into the 256-byte sfp, then memcpy(i2c->buffer, sfp, i2c->length) overflows the 64-byte buffer inside the on-stack array.
A caller holding CAP_SYS_RAWIO can use this to corrupt the heap and the kernel stack. Reject requests whose length exceeds the buffer before any copy or DMA transfer in both handlers.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 9ebb5d9c69f1f5721f9f6f49e501c674c1e184ae < 8f01f886cc5e7bbc16cbf1a9928fdebbc911e973 | affected |
| Linux | Linux | 9ebb5d9c69f1f5721f9f6f49e501c674c1e184ae < 2be39946abcde5a6416fb074ef728429e246a996 | affected |
| Linux | Linux | 9ebb5d9c69f1f5721f9f6f49e501c674c1e184ae < 522d6dcdc645d8f97d6b4cdfd6d8eea307f3ff0e | affected |
| Linux | Linux | 9ebb5d9c69f1f5721f9f6f49e501c674c1e184ae < 9a756f277eb89f769dbf380f38245c270d31fdb5 | affected |
| Linux | Linux | 9ebb5d9c69f1f5721f9f6f49e501c674c1e184ae < 32d6df14fdab71fe1ba304fd9a0db0411ea2e043 | affected |
| Linux | Linux | 9ebb5d9c69f1f5721f9f6f49e501c674c1e184ae < 97ca58b0fb026799b99e3d552d5f69cf9a3113ad | affected |
| Linux | Linux | 9ebb5d9c69f1f5721f9f6f49e501c674c1e184ae < 47049fdadc0eaa115e813735b827e1379c0d2cf8 | affected |
| Linux | Linux | 9ebb5d9c69f1f5721f9f6f49e501c674c1e184ae < 0918ee2c0eeb4d7f45b82b3dc11e65c2d9b7ad59 | affected |
| Linux | Linux | 3.7 | affected |
| Linux | Linux | 0 < 3.7 | unaffected |
| Linux | Linux | 5.10.270 <= 5.10.* | unaffected |
| Linux | Linux | 5.15.221 <= 5.15.* | unaffected |
| Linux | Linux | 6.1.188 <= 6.1.* | unaffected |
| Linux | Linux | 6.6.157 <= 6.6.* | unaffected |
| Linux | Linux | 6.12.110 <= 6.12.* | unaffected |
| Linux | Linux | 6.18.51 <= 6.18.* | unaffected |
| Linux | Linux | 7.2.5 <= 7.2.* | unaffected |
| Linux | Linux | 7.3-rc1 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/8f01f886cc5e7bbc16cbf1a9928fdebbc911e973
- https://git.kernel.org/stable/c/2be39946abcde5a6416fb074ef728429e246a996
- https://git.kernel.org/stable/c/522d6dcdc645d8f97d6b4cdfd6d8eea307f3ff0e
- https://git.kernel.org/stable/c/9a756f277eb89f769dbf380f38245c270d31fdb5
- https://git.kernel.org/stable/c/32d6df14fdab71fe1ba304fd9a0db0411ea2e043
- https://git.kernel.org/stable/c/97ca58b0fb026799b99e3d552d5f69cf9a3113ad
- https://git.kernel.org/stable/c/47049fdadc0eaa115e813735b827e1379c0d2cf8
- https://git.kernel.org/stable/c/0918ee2c0eeb4d7f45b82b3dc11e65c2d9b7ad59
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.