Answer in brief
CVE-2026-89458 records a Unknown severity vulnerability in s390/dasd: Do not complete a failed ESE read as successful. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=5e6bdd37c5526ef01326df5dabb93011ee89237e <c9adf8399732306dfc97b3adb4778038743e3f5e || >=5e6bdd37c5526ef01326df5dabb93011ee89237e <52b331c99baac653ca794bd8487c8ec4de8db203 || >=5e6bdd37c5526ef01326df5dabb93011ee89237e <b0d94dd6e82df396e2254c8b0f25eff7d19c2e7f || >=5e6bdd37c5526ef01326df5dabb93011ee89237e <cddb447c62466f3076938ce120028d7b591f9f37 || fbbacd0dcbc3ae9398c569dbea96ae4b5ad97e04 || 5f7c9989f11305aaa43e0f4378f4f070022a9f2b || >=5.4.26 <5.5 || >=5.5.10 <5.6 | c9adf8399732306dfc97b3adb4778038743e3f5e, 52b331c99baac653ca794bd8487c8ec4de8db203, b0d94dd6e82df396e2254c8b0f25eff7d19c2e7f, cddb447c62466f3076938ce120028d7b591f9f37, 5.5, 5.6 |
| Linux/Linuxgeneric | 5.6 | Not reported |
Published upstream
Sep 11, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 11, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 11, 2026
In the Linux kernel, the following vulnerability has been resolved: s390/dasd: Do not complete a failed ESE read as successful dasd_int_handler() completes an NRF read of an unallocated ESE track by calling ese_read() and unconditionally marking the request DASD_CQR_SUCCESS. dasd_eckd_ese_read() can return an error before it has zeroed the destination buffer: a failed sense-data parse or a current track outside the requested range both return early, leaving the destination pages untouched. The request is still completed successfully, so the block layer is handed stale / uninitialized memory instead of zeros. Check the ese_read() return value and fail the request through the normal error path instead of forcing DASD_CQR_SUCCESS.
Quoted source text, attributed separately from HOL analysis.