Use of Uninitialized Variable in Linux kernel - CVE-2026-89852
Published: September 17, 2026
Vulnerability details
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to use of an uninitialized variable in qla2x00_get_firmware_state() when querying firmware state through sysfs during a mailbox command failure. A local user can read firmware state through the fw_state or mpi_fw_state sysfs handlers during such a failure to disclose sensitive information.
Affected software
How to mitigate CVE-2026-89852
External References
- https://git.kernel.org/stable/c/13d645a2cdb224d27205368f3e3c68bb160daf97
- https://git.kernel.org/stable/c/1f49e861c18caf8eef7f0ad9a2c5034f88a6ba79
- https://git.kernel.org/stable/c/2f847f06bb223aa895eea91fc9e5e2d6314038eb
- https://git.kernel.org/stable/c/9efaa782845b4d5fb3e01242be0d06ebc7428d8f
- https://git.kernel.org/stable/c/9f31de4d07e4cde91dfc24522993a5fbb4d67083
- https://git.kernel.org/stable/c/e6cfb1ee18336aab41a0941d6d3ea5009aaafc05
- https://git.kernel.org/stable/c/f29695b1138ae2539c5cd6cdaba9b1b072aaa81a
- https://git.kernel.org/stable/c/f8fc5cc6b3284506c6ab83c822c48133377668bb