Improper Check or Handling of Exceptional Conditions in Linux kernel - CVE-2026-89456
Published: September 12, 2026
Vulnerability details
The vulnerability allows a local user to receive zeroed data for unread portions of a request.
The vulnerability exists due to improper handling of partial-completion length in dasd_default_erp_postaction() when recovering a partially completed ESE read through the ERP chain. A local user can issue a read request that is partially completed and recovered through the ERP chain to receive zeroed data for unread portions of a request.