{
  "affected": [
    {
      "ranges": [
        {
          "events": [
            {
              "introduced": "d74595278f4ab192af66d9e60a9087464638beee"
            },
            {
              "fixed": "cf623d32761b00f221a9cfded3303d56e84b429d"
            },
            {
              "fixed": "9eeddbeaa896f39d943644b16d83a6ad0ceab255"
            },
            {
              "fixed": "802068b9b683b8008fcccbf6e9ad133e597ec87c"
            },
            {
              "fixed": "e80adfeac61b4d5db7ffe0f5af43999c33a4145e"
            },
            {
              "fixed": "2efe50b2da829909023de4a2eb87badb7cfa53cc"
            },
            {
              "fixed": "7a448f5ed0b283dbde4e9183dd1e98c221432dab"
            },
            {
              "fixed": "33c77254e6e91f37c72c7fad4051777452b10de8"
            },
            {
              "fixed": "ebfd35c64433821bd5619a6d07ccc2df8b5b1de3"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        }
      ]
    },
    {
      "package": {
        "ecosystem": "Linux",
        "name": "Kernel"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "4.10.0"
            },
            {
              "fixed": "5.10.270"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "5.11.0"
            },
            {
              "fixed": "5.15.221"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "5.16.0"
            },
            {
              "fixed": "6.1.188"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.2.0"
            },
            {
              "fixed": "6.6.157"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.7.0"
            },
            {
              "fixed": "6.12.110"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.13.0"
            },
            {
              "fixed": "6.18.51"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.19.0"
            },
            {
              "fixed": "7.2.5"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "database_specific": {
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89856.json"
  },
  "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: qla2xxx: Clamp MSI-X derived queue counts to avoid truncation\n\nha-\u003emsix_count is u16, but ha-\u003emax_req_queues, ha-\u003emax_rsp_queues and\nha-\u003emax_qpairs are u8. Deriving the queue count as\n\"ha-\u003emax_req_queues = ha-\u003emsix_count - 1\" therefore truncates: a board\n(or a misconfigured/malicious hot-plugged device) advertising 257 MSI-X\nvectors yields msix_count - 1 == 256, which truncates to 0. An MSI-X\ncount of 1 zeroes it as well, and in target mode the subsequent\n\"ha-\u003emax_req_queues--\" then underflows 0 to 255.\n\nWhen the count is 0, qla2x00_alloc_queues() calls\nkzalloc_objs(struct req_que *, 0), which returns ZERO_SIZE_PTR. That is\nnot NULL, so the allocation check passes and the following\n\"ha-\u003ereq_q_map[0] = req\" dereferences ZERO_SIZE_PTR, corrupting memory\nor crashing the kernel.\n\nAdd qla_calc_queue_count() to clamp the derived value into\n[1, QLA_MAX_QUEUES - 1] so it always fits in u8 and is never zero, and\nuse it at all three derivation sites (qla25xx_iospace_config(),\nqla83xx_iospace_config() and qla24xx_enable_msix()). Also guard the\ntarget-mode decrement so it cannot reintroduce a zero (which would in\nturn underflow max_qpairs).",
  "id": "CVE-2026-89856",
  "modified": "2026-09-18T03:30:39.293264037Z",
  "published": "2026-09-16T10:31:29.517Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/2efe50b2da829909023de4a2eb87badb7cfa53cc"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/33c77254e6e91f37c72c7fad4051777452b10de8"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/7a448f5ed0b283dbde4e9183dd1e98c221432dab"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/802068b9b683b8008fcccbf6e9ad133e597ec87c"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/9eeddbeaa896f39d943644b16d83a6ad0ceab255"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/cf623d32761b00f221a9cfded3303d56e84b429d"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/e80adfeac61b4d5db7ffe0f5af43999c33a4145e"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/ebfd35c64433821bd5619a6d07ccc2df8b5b1de3"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89856.json"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-89856"
    },
    {
      "type": "PACKAGE",
      "url": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"
    }
  ],
  "schema_version": "1.9.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ],
  "summary": "scsi: qla2xxx: Clamp MSI-X derived queue counts to avoid truncation"
}