CVE-2026-89851
Received Received - Intake

BaseFortify

Vulnerability report for CVE-2026-89851, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-16

Last updated on: 2026-09-16

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix FCE trace enable parsing in debugfs qla2x00_dfs_fce_write() called kstrtoul() with a NULL result pointer, so a successful parse would dereference NULL and oops. Worse, the int return value (0 on success, negative errno on failure) was assigned to the unsigned long enable flag, inverting the intended logic: a valid number was treated as "disable" while a parse failure enabled FCE. Parse the value into enable and propagate parse errors to userspace.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-16
Last Modified
2026-09-16
Generated
2026-10-06
EPSS Evaluated
2026-10-05
NVD
EUVD

Affected Vendors & Products

Showing 16 associated CPEs
Vendor Product Version / Range
Linux Linux 3a5a789494875376d1f8063ec5ecc6beafda2ce1
Linux Linux 73d3d3c66f108bc47922490f8500842530139975
Linux Linux 57c029cab0d908942e3ed9ff9fd0361144d01944
Linux Linux 217230bc8796a922d5b15a9a94ec4414b2d2b3e3
Linux Linux 2cf3c3fe9a11aa168e80c966494c58548b9aed5d
Linux Linux 841df27d619ee1f5ca6473e15227b39d6136562d
Linux Linux 841df27d619ee1f5ca6473e15227b39d6136562d
Linux Linux 841df27d619ee1f5ca6473e15227b39d6136562d
Linux Linux a89872a61b914378591f16e428dd221c5e2059b2
Linux Linux 5.10.235
Linux Linux 5.15.179
Linux Linux 6.1.129
Linux Linux 6.6.78
Linux Linux 6.12.14
Linux Linux 6.13.3
Linux Linux 6.14

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
AI Quick Actions have not been generated yet.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89851. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart