Answer in brief
CVE-2026-89849 records a Unknown severity vulnerability in scsi: qla2xxx: Reject non-SCSI SRB on status IOCB fast path. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=dd30706e73b70d67e88fdaca688db7a3374fd5de <9204fb0888374083be74f799049649a17eab4191 || >=dd30706e73b70d67e88fdaca688db7a3374fd5de <b7418198b45b327194b97f856fe8ea8daa91f3fd || >=dd30706e73b70d67e88fdaca688db7a3374fd5de <8f0e31e7a41376abe7d6ca7cbee07fcf9de071e6 || >=dd30706e73b70d67e88fdaca688db7a3374fd5de <e38041b47c29316ba79b645e2ae0b713d216b1db || >=dd30706e73b70d67e88fdaca688db7a3374fd5de <e93aa3c5125d9a4352ac0fa8ba4a7f8f87881805 || >=dd30706e73b70d67e88fdaca688db7a3374fd5de <29f1f9ad9e354cd0b6e4f6fc75ba09162d6a04d9 || >=dd30706e73b70d67e88fdaca688db7a3374fd5de <0f41d07d72f2245208c45374ca8d0a1846cad667 | 9204fb0888374083be74f799049649a17eab4191, b7418198b45b327194b97f856fe8ea8daa91f3fd, 8f0e31e7a41376abe7d6ca7cbee07fcf9de071e6, e38041b47c29316ba79b645e2ae0b713d216b1db, e93aa3c5125d9a4352ac0fa8ba4a7f8f87881805, 29f1f9ad9e354cd0b6e4f6fc75ba09162d6a04d9, 0f41d07d72f2245208c45374ca8d0a1846cad667 |
| Linux/Linuxgeneric | 5.15 | Not reported |
Published upstream
Sep 16, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 16, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 16, 2026
In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Reject non-SCSI SRB on status IOCB fast path qla2x00_status_entry() filters out non-TYPE_SRB entries and the SRB_NVME_CMD, SRB_BIDI_CMD and SRB_TM_CMD types, then falls through to a SCSI fast path that assumes the command is an SRB_SCSI_CMD. The first thing on that path, qla_chk_edif_rx_sa_delete_pending(), and the subsequent handling both evaluate GET_CMD_SP(sp), i.e. sp->u.scmd.cmd. The srb u union overlays the SCSI command pointer with other command layouts (bsg_job, iocb_cmd). If firmware delivers an unexpected STATUS_TYPE IOCB for a non-SCSI handle, sp->u.scmd.cmd can read as a non-NULL garbage pointer, bypassing the NULL checks in qla_chk_edif_rx_sa_delete_pending() and at the cp == NULL test, and leading to a wild pointer dereference. Reject any SRB whose type is not SRB_SCSI_CMD before entering the fast path. The outstanding_cmds slot is left untouched so a genuinely non-SCSI command still completes through its proper handler.
Quoted source text, attributed separately from HOL analysis.