SB20260917116 - Use of Uninitialized Variable in Linux kernel scsi qla2xxx driver
Published: September 17, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Use of Uninitialized Variable (CVE-ID: CVE-2026-89852)
CWE-ID: CWE-457 - Use of Uninitialized Variable
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to use of an uninitialized variable in qla2x00_get_firmware_state() when querying firmware state through sysfs during a mailbox command failure. A local user can read firmware state through the fw_state or mpi_fw_state sysfs handlers during such a failure to disclose sensitive information.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/13d645a2cdb224d27205368f3e3c68bb160daf97
- https://git.kernel.org/stable/c/1f49e861c18caf8eef7f0ad9a2c5034f88a6ba79
- https://git.kernel.org/stable/c/2f847f06bb223aa895eea91fc9e5e2d6314038eb
- https://git.kernel.org/stable/c/9efaa782845b4d5fb3e01242be0d06ebc7428d8f
- https://git.kernel.org/stable/c/9f31de4d07e4cde91dfc24522993a5fbb4d67083
- https://git.kernel.org/stable/c/e6cfb1ee18336aab41a0941d6d3ea5009aaafc05
- https://git.kernel.org/stable/c/f29695b1138ae2539c5cd6cdaba9b1b072aaa81a
- https://git.kernel.org/stable/c/f8fc5cc6b3284506c6ab83c822c48133377668bb