← Back to search

CVE-2026-89849

8.8 HIGH

Published 2026-09-16 · Updated 2026-09-16

AI risk analysis

Summary
This vulnerability in the Linux kernel's qla2xxx driver allows an attacker to cause a wild pointer dereference by sending a non-SCSI SRB with a non-null garbage pointer, potentially leading to a denial of service or other kernel crashes.
Exploitability
Exploitation requires sending a crafted non-SCSI SRB to the affected driver, which may be difficult if the network or device is not exposed to untrusted entities.
Blast radius
If exploited, the impact is limited to the local system, potentially causing a denial of service or kernel panic.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to the latest kernel version 6.2.0 or later.
kerneldenial-of-servicelocal-privilege-escalation

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Reject non-SCSI SRB on status IOCB fast path qla2x00_status_entry() filters out non-TYPE_SRB entries and the SRB_NVME_CMD, SRB_BIDI_CMD and SRB_TM_CMD types, then falls through to a SCSI fast path that assumes the command is an SRB_SCSI_CMD. The first thing on that path, qla_chk_edif_rx_sa_delete_pending(), and the subsequent handling both evaluate GET_CMD_SP(sp), i.e. sp->u.scmd.cmd. The srb u union overlays the SCSI command pointer with other command layouts (bsg_job, iocb_cmd). If firmware delivers an unexpected STATUS_TYPE IOCB for a non-SCSI handle, sp->u.scmd.cmd can read as a non-NULL garbage pointer, bypassing the NULL checks in qla_chk_edif_rx_sa_delete_pending() and at the cp == NULL test, and leading to a wild pointer dereference. Reject any SRB whose type is not SRB_SCSI_CMD before entering the fast path. The outstanding_cmds slot is left untouched so a genuinely non-SCSI command still completes through its proper handler.

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.