From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id AE09E552958 for ; Fri, 11 Sep 2026 19:54:46 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789156493; cv=none; b=uU0r39dM5yIT4OHaIeWH1PJDLzEtitG0tSo4yYiN5mVtziLWYdAlsaOzLilMXXIPQ8aArcWHX5dVQyeO2DzZfPvouibLJAaSNeL4kVHtcfO5dvUk39cDwcc5105uXQoMAHbdt9hnbVLep7150dpUfSVmqdjmXJOk7OxaWXTtJUg= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789156493; c=relaxed/simple; bh=e5XYC2Fo0390BNt65HH7Vjbtsy+8aNpikYgs/9TNJeY=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=fazW9OvqAOblmEk9UmU1Va9eHpr5HoH04V/8g0Q1TL04La2hdIljVGPqQYbl8C6m71LNgIYcMShracg7V3jsSZhAHOt360i6qZizUrA2MTQjUQ3AMFWZCvvPz7JGOQrD0uyH75wTJkBG6jTiy7aFUcx2QXttmgKJq3am16OAF4w= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=smSqdGmt; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="smSqdGmt" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 171F51F000FF; Fri, 11 Sep 2026 19:54:41 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1789156482; bh=FIQRVq8LZrJBe84nMAXbIkSKraxIji0T6rof4WgcyRM=; h=From:To:Cc:Subject:Date:Reply-To; b=smSqdGmttsmtah5u6/9Qy5PSJUoJpy8kXCIn6R2pbAoyhtNyilM/L2BhIkRVLLTpe 92J+ycv4hNN34yaAZQetRbG+zj/v2ePulVaBX7FxpA/5inWRqtvbxYOYGnyp99L58A MYFsZKOimq/jRmptjl6IV4VhFGqYkUCC4cXt/pxk= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-89515: scsi: core: Fill in DMA padding bytes in scsi_alloc_sgtables() Date: Fri, 11 Sep 2026 21:43:24 +0200 Message-ID: <2026091113-CVE-2026-89515-678b@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=4129; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=6Qzk8L5Jbd0MEcMeNvkB7o4E9JeZLVfEG/mUROY38x4=; b=owGbwMvMwCRo6H6F97bub03G02pJDFlLIiNf/Qi4pFrV6pdbVSi+UC5ZUXvaCvcNtp7359spS My5zyDYEcvCIMjEICumyPJlG8/R/RWHFL0MbU/DzGFlAhnCwMUpABNZKcqw4CTT56lM4TxGx+7X px2cWiPipzl7G8P8wB254hGbb6lrhsls0Ss9alop+f4AAA== X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: scsi: core: Fill in DMA padding bytes in scsi_alloc_sgtables() During fuzz testing, the following issue was discovered: BUG: KMSAN: uninit-value in __dma_map_sg_attrs+0x217/0x310 __dma_map_sg_attrs+0x217/0x310 dma_map_sg_attrs+0x4a/0x70 ata_qc_issue+0x9f8/0x1420 __ata_scsi_queuecmd+0x1657/0x1740 ata_scsi_queuecmd+0x79a/0x920 scsi_queue_rq+0x4472/0x4f40 blk_mq_dispatch_rq_list+0x1cca/0x3ee0 __blk_mq_sched_dispatch_requests+0x458/0x630 blk_mq_sched_dispatch_requests+0x15b/0x340 __blk_mq_run_hw_queue+0xe5/0x250 __blk_mq_delay_run_hw_queue+0x138/0x780 blk_mq_run_hw_queue+0x4bb/0x7e0 blk_mq_sched_insert_request+0x2a7/0x4c0 blk_execute_rq+0x497/0x8a0 sg_io+0xbe0/0xe20 scsi_ioctl+0x2b36/0x3c60 sr_block_ioctl+0x319/0x440 blkdev_ioctl+0x80f/0xd70 __se_sys_ioctl+0x219/0x420 __x64_sys_ioctl+0x93/0xe0 x64_sys_call+0x1d6c/0x3ad0 do_syscall_64+0x4c/0xa0 entry_SYSCALL_64_after_hwframe+0x6e/0xd8 Uninit was created at: __alloc_pages+0x5c0/0xc80 alloc_pages+0xe0e/0x1050 blk_rq_map_user_iov+0x2b77/0x6100 blk_rq_map_user_io+0x2fa/0x4d0 sg_io+0xad6/0xe20 scsi_ioctl+0x2b36/0x3c60 sr_block_ioctl+0x319/0x440 blkdev_ioctl+0x80f/0xd70 __se_sys_ioctl+0x219/0x420 __x64_sys_ioctl+0x93/0xe0 x64_sys_call+0x1d6c/0x3ad0 do_syscall_64+0x4c/0xa0 entry_SYSCALL_64_after_hwframe+0x6e/0xd8 Bytes 14-15 of 16 are uninitialized Memory access of size 16 starts at ffff88800cbdb000 When processing the last unaligned element of the scatterlist, it is supplemented with missing bytes in the amount of pad_len. These bytes remain uninitialized, which leads to a problem. Extend last_sg->length by pad_len first, then use sg_zero_buffer() to zero those pad_len bytes. sg_zero_buffer() uses sg_miter internally, which correctly handles sg entries spanning multiple pages and padding that crosses a page boundary. Found by Linux Verification Center (linuxtesting.org) with Syzkaller. The Linux kernel CVE team has assigned CVE-2026-89515 to this issue. Affected and fixed versions =========================== Issue introduced in 2.6.25 with commit 40b01b9bbdf51ae543a04744283bf2d56c4a6afa and fixed in 6.12.109 with commit a4353ec7742bdf87dcdde5875270feb3a1982a51 Issue introduced in 2.6.25 with commit 40b01b9bbdf51ae543a04744283bf2d56c4a6afa and fixed in 6.18.50 with commit e7143c3f4e5c0a7986733c6f27009274bf6c4264 Issue introduced in 2.6.25 with commit 40b01b9bbdf51ae543a04744283bf2d56c4a6afa and fixed in 7.2.4 with commit 6fd1cce5018fdcc8d928e00a6a1dd2997d5b9409 Issue introduced in 2.6.25 with commit 40b01b9bbdf51ae543a04744283bf2d56c4a6afa and fixed in 7.3-rc1 with commit 626147717bea776b61ed3631d2c26283760c4cc4 Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-89515 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: drivers/scsi/scsi_lib.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/a4353ec7742bdf87dcdde5875270feb3a1982a51 https://git.kernel.org/stable/c/e7143c3f4e5c0a7986733c6f27009274bf6c4264 https://git.kernel.org/stable/c/6fd1cce5018fdcc8d928e00a6a1dd2997d5b9409 https://git.kernel.org/stable/c/626147717bea776b61ed3631d2c26283760c4cc4