{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  ata: libata-scsi: fix DSM TRIM for sector sizes larger than 2048 bytes  ata_scsi_write_same_xlat() translates a SCSI WRITE SAME command with the UNMAP bit set into an ATA DATA SET MANAGEMENT TRIM command.  The TRIM descriptor is built by ata_format_dsm_trim_descr() into the 2048-byte ata_scsi_rbuf staging buffer, and the number of bytes copied is compared against the logical sector size by the caller:  \tsize = ata_format_dsm_trim_descr(scmd, trmax, block, n_block); \tif (size != len)\t\t/* len == sdp-\u003esector_size */ \t\tgoto invalid_param_len;  ata_format_dsm_trim_descr() clamps the copy length to ATA_SCSI_RBUF_SIZE (2048).  On a device whose logical sector size exceeds that (e.g. a 4Kn device, where sector_size == 4096) the function can never return more than 2048, while the caller expects it to return sector_size.  The comparison therefore always fails, so every TRIM is rejected with \"Parameter list length error\" and WARN_ON() splats on each attempt.  TRIM / discard is thus completely broken on such devices.  The descriptor was incorrectly sized from the logical sector size.  A DSM TRIM payload is a list of 512-byte pages, each holding up to ATA_MAX_TRIM_RNUM (64) LBA Range Entries, and is independent of the logical sector size.  The Block Limits VPD page already advertises a single such page as the maximum WRITE SAME length (65535 * ATA_MAX_TRIM_RNUM logical blocks), so the block layer never sends a request that needs more than one page.  Emit exactly one 512-byte page, independent of the logical sector size, and transfer only that page (COUNT == 1).  For a 512-byte-sector device this is unchanged; devices with larger logical sectors now work instead of failing every TRIM.",
  "id": "DEBIAN-CVE-2026-89586",
  "modified": "2026-09-14T08:47:38.824775564Z",
  "published": "2026-09-11T20:19:43.040Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-89586"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
      "type": "CVSS_V3"
    }
  ],
  "upstream": [
    "CVE-2026-89586"
  ]
}