Answer in brief
CVE-2026-89852 records a Unknown severity vulnerability in scsi: qla2xxx: Zero mailbox struct in qla2x00_get_firmware_state(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=4d4df1932b6b116aecc81039066fec27f2050762 <f8fc5cc6b3284506c6ab83c822c48133377668bb || >=4d4df1932b6b116aecc81039066fec27f2050762 <f29695b1138ae2539c5cd6cdaba9b1b072aaa81a || >=4d4df1932b6b116aecc81039066fec27f2050762 <13d645a2cdb224d27205368f3e3c68bb160daf97 || >=4d4df1932b6b116aecc81039066fec27f2050762 <2f847f06bb223aa895eea91fc9e5e2d6314038eb || >=4d4df1932b6b116aecc81039066fec27f2050762 <1f49e861c18caf8eef7f0ad9a2c5034f88a6ba79 || >=4d4df1932b6b116aecc81039066fec27f2050762 <e6cfb1ee18336aab41a0941d6d3ea5009aaafc05 || >=4d4df1932b6b116aecc81039066fec27f2050762 <9f31de4d07e4cde91dfc24522993a5fbb4d67083 || >=4d4df1932b6b116aecc81039066fec27f2050762 <9efaa782845b4d5fb3e01242be0d06ebc7428d8f | f8fc5cc6b3284506c6ab83c822c48133377668bb, f29695b1138ae2539c5cd6cdaba9b1b072aaa81a, 13d645a2cdb224d27205368f3e3c68bb160daf97, 2f847f06bb223aa895eea91fc9e5e2d6314038eb, 1f49e861c18caf8eef7f0ad9a2c5034f88a6ba79, e6cfb1ee18336aab41a0941d6d3ea5009aaafc05, 9f31de4d07e4cde91dfc24522993a5fbb4d67083, 9efaa782845b4d5fb3e01242be0d06ebc7428d8f |
| Linux/Linuxgeneric | 2.6.26 | Not reported |
Published upstream
Sep 16, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 16, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 16, 2026
In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Zero mailbox struct in qla2x00_get_firmware_state() The mbx_cmd_t is allocated on the stack but left uninitialized. qla2x00_mailbox_command() has several early-return paths (PCI permanent failure, device failed, EEH busy, ISP abort pending, mailbox access timeout, purge mbox) that return without writing the input mailbox registers back into mcp->mb[]. qla2x00_get_firmware_state() then unconditionally copies mcp->mb[1..6] (and mb[12]) into the caller's states[] array regardless of the return value. On such a failure the copied values are uninitialized kernel stack memory, which is then exposed to userspace via the fw_state and mpi_fw_state sysfs handlers. Zero the mailbox struct so a failed query yields deterministic zeroed state instead of leaking stack contents.
Quoted source text, attributed separately from HOL analysis.