Database/Kernel, userspace & hypervisor
Linux qla2xxx: D_Port diagnostics copies uninitialized kernel heap bytes to user space
Impact
qla2x00_do_dport_diagnostics() allocates the response buffer without zeroing it and then copies the full structure back to user space, so the options and unused[] fields carry whatever was left in kernel heap memory. A local user able to issue the bsg diagnostics request against a QLogic Fibre Channel HBA gets a small, repeatable window into kernel heap contents, which is useful for defeating KASLR or recovering fragments of other kernel data before a second bug. GPU nodes that mount Fibre Channel storage carry this driver; the exposure is limited to whoever can reach the FC transport bsg interface, normally root or a storage-management account, which keeps this firmly in the information-disclosure tier rather than direct escalation. No CVSS score is published in the record.
Who can reach it
Local user with access to the Fibre Channel bsg/SG interface of a qla2xxx HBA - in a default configuration that means root or a privileged storage-management role. No remote path.
What to do
Take the stable-tree fix (switch to a zeroing allocation) in the kernel builds for hosts with QLogic FC HBAs and reboot those nodes on a normal maintenance window; the exposure is low enough that it can ride along with the next scheduled kernel update rather than an emergency drain. No fixed distribution version is named in the record.
References
Related entries
- Linux kernel arm-smmu-v3: device teardown frees the IOPF queue before the IRQ handler that uses itCVE-2026-93205 · Linux kernel iommu/arm-smmu-v3 (teardown ordering in arm_smmu_device_remove)Unscored
- Linux kernel PCI/proc: config space read checked against the reader's credentials, not the opener'sCVE-2026-93206 · Linux kernel PCI procfs interface (proc_bus_pci_read CAP_SYS_ADMIN check)Unscored
- Linux kernel BPF: sysctl value replaced by a BPF program is not NUL-terminated, giving out-of-bounds readsCVE-2026-97420 · Linux kernel BPF (bpf_sysctl_set_new_value replacement buffer)Unscored
- Linux kernel net/rds: unprivileged container reads every RDS socket and connection on the hostCVE-2026-97476 · Linux kernel net/rds RDS_INFO_* getsockopt (missing netns filtering)Unscored
- Linux kernel net/rds: RDS-over-IB shutdown sleeps in a shared worker and hangs fabric teardownCVE-2026-97491 · Linux kernel net/rds over InfiniBand (rds_ib_conn_path_shutdown sleeping in the shutdown worker)Unscored
- Linux PCI sysfs: BAR resize via resourceN_resize had no CAP_SYS_ADMIN checkCVE-2026-97505 · Linux kernel PCI sysfs (resourceN_resize, __resource_resize_store)Unscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.