Kernel heap exposure via uninitialized SFP DMA buffer
Published Sep 16, 2026 · Updated Sep 16, 2026
Uninitialized-memory exposure in Linux qla2xxx allows attackers to write stale kernel heap data to adapter flash through crafted bsg payloads. Five FRU and I2C handlers allocate a 256-byte DMA buffer without zeroing it, initialize only a short prefix, and let qla2x00_write_sfp replace the transfer length with a payload byte of up to 255. Reachability requires a qla2xxx adapter and access to a FRU or I2C bsg handler; the published record does not specify the required host privileges.
Summary
What happened
Uninitialized-memory exposure in Linux qla2xxx allows attackers to write stale kernel heap data to adapter flash through crafted bsg payloads. Five FRU and I2C handlers allocate a 256-byte DMA buffer without zeroing it, initialize only a short prefix, and let qla2x00_write_sfp replace the transfer length with a payload byte of up to 255. Reachability requires a qla2xxx adapter and access to a FRU or I2C bsg handler; the published record does not specify the required host privileges.
The record
- CVE
- CVE-2026-89865
- Published
- Sep 16, 2026
- Updated
- Sep 16, 2026
- Vendor
- The Linux Kernel Organization
- Product
- Linux
- Classifications
- Unavailable
- Attack vector
- local
- Privileges
- Unavailable
Timeline
How it unfolded
- Sep 16, 2026CVE publishedPublication date reported by the CVE source.
- Sep 16, 2026Record updatedLatest update available in the CVE record.
Exploitability
Present is not the same as exploitable
Compare your product and version with the public record. A matching version still requires validation against your environment.
Is a vulnerable build present?
Compare these published version ranges with your installed build and any vendor patches.
- Affected versionversion=3.2
- Affected versionversion=697a4bc69159c3396035b0506ffa55c4b2d0b1f4 <09703bc7c0be3a7a155b0ff5f21f6765ba3f519c
- Affected versionversion=697a4bc69159c3396035b0506ffa55c4b2d0b1f4 <581590f560b74399151b3cbc88574424c2f3d2dc
- Affected versionversion=697a4bc69159c3396035b0506ffa55c4b2d0b1f4 <84bde5ce4038d9ad811e5c994305bbfcbd7a9f79
- Affected versionversion=697a4bc69159c3396035b0506ffa55c4b2d0b1f4 <97c45c75f5cdec96b1a4fba8b1d55d0dd01af1e8
- Affected versionversion=697a4bc69159c3396035b0506ffa55c4b2d0b1f4 <a476377a66897549dd49bee319f4df66623417b7
- Affected versionversion=697a4bc69159c3396035b0506ffa55c4b2d0b1f4 <a5501c42256235523c4dddf799f032dfbf4f4c77
- Affected versionversion=697a4bc69159c3396035b0506ffa55c4b2d0b1f4 <b157256c28086c434afd70cc78bf9b4d8caf1276
- Affected versionversion=697a4bc69159c3396035b0506ffa55c4b2d0b1f4 <b47d4a1547d9ef21b2e9d1a739fe2204d4be05dc
What conditions does exploitation require?
What is affected?
Published CVSS scores
No CVSS assessment is available in this record.
CVSS describes severity. EPSS estimates exploitation probability.
Attacks
What attackers are doing with it
Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.
Weakness, pattern, technique
No sourced classifications are available.
Public exploit references
No public exploit references are available in this record.
Labels summarize the accepted research assessment. They do not indicate a test against your environment.
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo