CVE-2026-89456
Received Received - Intake

s390/dasd Partial Completion Length Loss in Linux Kernel

Vulnerability report for CVE-2026-89456, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-14

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: s390/dasd: Propagate partial completion length across ERP recovery dasd_default_erp_postaction() copies the timing and device state from the finished ERP request back to the original request but drops proc_bytes. A request that was partially completed, an ESE read of a not-yet-allocated track returns fewer bytes than requested, and then recovered through the ERP chain loses its partial-completion length. __dasd_cleanup_cqr() then sees proc_bytes == 0 and completes the whole request instead of requeueing the remainder, silently returning zeroed data for the part that was never read. Carry proc_bytes over to the original request like the other per-request state.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-14
Generated
2026-10-02
AI Q&A
2026-09-12
EPSS Evaluated
2026-10-01
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux linux_kernel *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel affects the s390/dasd driver. When a request is partially completed and then recovered through error recovery processing (ERP), the system fails to properly track the number of bytes already processed. This causes the system to incorrectly report the request as fully completed, returning zeroed data for the unread portion instead of retrying to read the remaining data.

Detection Guidance

This vulnerability is specific to the Linux kernel's s390/dasd driver and involves partial completion handling during error recovery. Detection requires checking kernel logs for DASD-related errors or unusual read operations on s390 systems. No direct commands are provided in the context, but monitoring for 'dasd' errors in dmesg or journalctl logs may help identify affected systems.

Impact Analysis

If exploited, this flaw could lead to data corruption or loss when reading from storage devices. Applications relying on accurate data retrieval may receive incorrect or incomplete information, potentially causing crashes, incorrect operations, or security issues depending on the affected system's use case.

Compliance Impact

This vulnerability could impact compliance by causing data integrity issues, which are critical under regulations like GDPR and HIPAA. If personal or sensitive data is corrupted or lost due to this flaw, organizations may violate data protection requirements, leading to legal penalties, reputational damage, or loss of certification.

Mitigation Strategies

Apply the latest Linux kernel patches to address the s390/dasd driver issue. Since this is a kernel-level vulnerability, updating to a patched kernel version is the primary mitigation. Monitor vendor advisories for kernel updates specific to your distribution.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89456. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart