CVE-2026-89846 PUBLISHED

scsi: qla2xxx: Bound rsp_info_len to avoid OOB sense-data read

Assigner: Linux
Reserved: 11.09.2026 Published: 16.09.2026 Updated: 16.09.2026

In the Linux kernel, the following vulnerability has been resolved:

scsi: qla2xxx: Bound rsp_info_len to avoid OOB sense-data read

In qla2x00_status_entry(), the FWI2 status path advances sense_data and shrinks par_sense_len by rsp_info_len:

<pre>if (IS_FWI2_CAPABLE(ha)) { sense_data += rsp_info_len; par_sense_len -= rsp_info_len; } </pre>

rsp_info_len is a 32-bit value taken directly from the target's FCP response (sf.rsp_data_len), while par_sense_len is the IOCB data area size (28 bytes for 24xx, 60 bytes for 29xx). A hostile or buggy target reporting an rsp_info_len larger than par_sense_len makes the unsigned subtraction underflow to a huge value and advances sense_data out of bounds.

The underflowed par_sense_len then defeats the cap in qla2x00_handle_sense():

<pre>if (sense_len > par_sense_len) sense_len = par_sense_len; memcpy(cp->sense_buffer, sense_data, sense_len); </pre>

so the memcpy reads up to SCSI_SENSE_BUFFERSIZE bytes from the out-of-bounds sense_data pointer, leaking adjacent response-ring/heap memory into the command's sense buffer.

Clamp rsp_info_len to par_sense_len before the subtraction so par_sense_len can never underflow and sense_data stays within the IOCB data area. The fix sits before the comp_status switch, covering both qla2x00_handle_sense() call sites.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
CVSS Score: 9.1

AV:N - qla2xxx builds initiator status IOCBs from a remote Fibre Channel or FCoE target's FCP_RSP; QLogic CNAs speak FCoE and SAN fabrics are stretched across sites via FCIP/inter-fabric routing, so a malicious or compromised target delivers the crafted rsp_data_len over the storage network with no local access. AC:L - A hostile target fully controls FCP_RSP (SS_RESPONSE_INFO_LEN_VALID, rsp_data_len, sense_len, CHECK CONDITION, rsp_info[3]==0) and can return them on ordinary initiator I/O such as INQUIRY during fabric scan; no race, rare config, or victim state beyond a FWI2-capable HBA is required. PR:N - Completions are handled in the HBA interrupt/response-queue path (qla24xx_process_response_queue to qla2x00_status_entry) with no Linux credential or capability check; the attacker only needs to act as an FC/FCoE target on the fabric. UI:N - Once the target is visible on the fabric, the SCSI midlayer automatically issues commands (scan, path checks, mounted-filesystem I/O) whose STATUS_TYPE completions take the vulnerable path; no user mount, open, or other interactive step is required at exploit time. S:U - The out-of-bounds read and any resulting oops stay inside the host kernel that owns the qla2xxx driver and do not cross a VM, IOMMU, or other separate security authority. C:H - Attacker-controlled 32-bit rsp_info_len advances sense_data out of the 28-byte IOCB data area and underflows par_sense_len so qla2x00_handle_sense() copies up to SCSI_SENSE_BUFFERSIZE (96) bytes of adjacent response-ring or kernel memory into the command sense buffer, which userspace can read via SCSI completion, SG_IO, and BSG. I:N - The memcpy destination is the in-bounds SCSI sense buffer already capped at SCSI_SENSE_BUFFERSIZE; this is a source over-read only, with no out-of-bounds write, use-after-free, or control-flow hijack primitive. A:H - Adding a 32-bit attacker-chosen rsp_info_len to sense_data yields a wild kernel pointer; memcpy from an unmapped address in the interrupt-context response-queue path oopses or panics the host, and the target can repeat this on every command.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 5544213be7b4fb693730106a6d70a8cc1aa7cdf6 to 125b12861c726e58448bb95d55b04851fb131d1f (excl.)
  • affected from 5544213be7b4fb693730106a6d70a8cc1aa7cdf6 to e57ace988bda5693f7b3645f652ea4b4220870ee (excl.)
  • affected from 5544213be7b4fb693730106a6d70a8cc1aa7cdf6 to 6b08c0cb110a1fba92f99d655020198489699815 (excl.)
  • affected from 5544213be7b4fb693730106a6d70a8cc1aa7cdf6 to be75ab791c9b3baca66c70ce03443afebc83acda (excl.)
  • affected from 5544213be7b4fb693730106a6d70a8cc1aa7cdf6 to ebc41dfc59d190956e0113e8bd90c28f6f21e8b9 (excl.)
  • affected from 5544213be7b4fb693730106a6d70a8cc1aa7cdf6 to d7f7746ff031ae45724881261804f4bf5317c985 (excl.)
  • affected from 5544213be7b4fb693730106a6d70a8cc1aa7cdf6 to f6e8977bce887481b2b2b0e2e14a791270741cfb (excl.)
  • affected from 5544213be7b4fb693730106a6d70a8cc1aa7cdf6 to ca6d880d6c70cb7946e7b3e05d7285f271b6d99e (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 2.6.36 is affected
  • unaffected from 0 to 2.6.36 (excl.)
  • unaffected from 5.10.270 to 5.10.* (incl.)
  • unaffected from 5.15.221 to 5.15.* (incl.)
  • unaffected from 6.1.188 to 6.1.* (incl.)
  • unaffected from 6.6.157 to 6.6.* (incl.)
  • unaffected from 6.12.110 to 6.12.* (incl.)
  • unaffected from 6.18.51 to 6.18.* (incl.)
  • unaffected from 7.2.5 to 7.2.* (incl.)
  • unaffected from 7.3-rc1 to * (incl.)

References