Answer in brief
CVE-2026-89858 records a Unknown severity vulnerability in scsi: qla2xxx: Bound image count in qla2x00_update_fru_versions(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=697a4bc69159c3396035b0506ffa55c4b2d0b1f4 <af733bbfcf667af1871a2735fba2835b0da71efb || >=697a4bc69159c3396035b0506ffa55c4b2d0b1f4 <a9706d5e754e77515a92bb532bd0d73644979a1f || >=697a4bc69159c3396035b0506ffa55c4b2d0b1f4 <7e3154c97ec15460f715dbbe4097c255cce110b1 || >=697a4bc69159c3396035b0506ffa55c4b2d0b1f4 <047f1f7ee6f85bde28abfdda9fa550191ddc0532 || >=697a4bc69159c3396035b0506ffa55c4b2d0b1f4 <f93e8039e6fd54a3c027c6184daf00b745b576a0 || >=697a4bc69159c3396035b0506ffa55c4b2d0b1f4 <7b22b4cb8822805cef7ba618da6f76e1474d68bd || >=697a4bc69159c3396035b0506ffa55c4b2d0b1f4 <f2d4f025b67fcbfb2bbbadd3b5a6a43c4b436514 || >=697a4bc69159c3396035b0506ffa55c4b2d0b1f4 <de62cf265dbe309f34f144a6cdbca9240317727e | af733bbfcf667af1871a2735fba2835b0da71efb, a9706d5e754e77515a92bb532bd0d73644979a1f, 7e3154c97ec15460f715dbbe4097c255cce110b1, 047f1f7ee6f85bde28abfdda9fa550191ddc0532, f93e8039e6fd54a3c027c6184daf00b745b576a0, 7b22b4cb8822805cef7ba618da6f76e1474d68bd, f2d4f025b67fcbfb2bbbadd3b5a6a43c4b436514, de62cf265dbe309f34f144a6cdbca9240317727e |
| Linux/Linuxgeneric | 3.2 | Not reported |
Published upstream
Sep 16, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 16, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 16, 2026
In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Bound image count in qla2x00_update_fru_versions() qla2x00_update_fru_versions() copies the user-supplied BSG request into a fixed 256-byte stack buffer (bsg[DMA_POOL_SIZE]) and then iterates list->count times over the qla_image_version array embedded in that buffer, advancing the image pointer each iteration. count is taken directly from user input with no upper bound, while only (DMA_POOL_SIZE - sizeof(list->count)) / sizeof(struct qla_image_version) = 6 entries actually fit. A larger count walks the image pointer off the end of the stack buffer, reading adjacent kernel stack memory and sending it to the device via qla2x00_write_sfp(). Reject requests whose declared count does not fit in the buffer.
Quoted source text, attributed separately from HOL analysis.