GPU VulnDB

Database/Kernel, userspace & hypervisor

Linux qla2xxx: D_Port diagnostics copies uninitialized kernel heap bytes to user space

UnscoredCVE-2026-89859Kernel, userspace & hypervisorcurated

Impact

qla2x00_do_dport_diagnostics() allocates the response buffer without zeroing it and then copies the full structure back to user space, so the options and unused[] fields carry whatever was left in kernel heap memory. A local user able to issue the bsg diagnostics request against a QLogic Fibre Channel HBA gets a small, repeatable window into kernel heap contents, which is useful for defeating KASLR or recovering fragments of other kernel data before a second bug. GPU nodes that mount Fibre Channel storage carry this driver; the exposure is limited to whoever can reach the FC transport bsg interface, normally root or a storage-management account, which keeps this firmly in the information-disclosure tier rather than direct escalation. No CVSS score is published in the record.

Who can reach it

Local user with access to the Fibre Channel bsg/SG interface of a qla2xxx HBA - in a default configuration that means root or a privileged storage-management role. No remote path.

What to do

Take the stable-tree fix (switch to a zeroing allocation) in the kernel builds for hosts with QLogic FC HBAs and reboot those nodes on a normal maintenance window; the exposure is low enough that it can ride along with the next scheduled kernel update rather than an emergency drain. No fixed distribution version is named in the record.

References

Related entries

All Kernel, userspace & hypervisor entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.