CVE-2026-98232
Received Received - Intake

Linux Kernel SCSI CDL Length Validation Flaw

Vulnerability report for CVE-2026-98232, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: scsi: core: Validate MODE SENSE lengths in scsi_cdl_enable() scsi_cdl_enable() uses length fields returned by MODE SENSE to locate the ATA feature mode page in a 64-byte stack buffer. A target can report a total length shorter than its mode header and block descriptors. The unsigned subtraction used for the MODE SELECT length can wrap, and the separately computed buf_data can point beyond buf. During automatic scan, enable is false, so the read-modify-write of buf_data[4] can clear the low two bits of a target-selected out-of-bounds stack byte. scsi_mode_select() can then copy up to 64 bytes from outside the buffer into the outgoing MODE SELECT payload, disclosing stack contents to the target. This is reachable while scanning a USB storage device that identifies as an ATA device and advertises CDL support. No filesystem mount or userspace access to the block device is required. On upstream commit cee9395acd80 ("Linux 7.3-rc1"), a build-specific, one-vCPU QEMU/Raw Gadget proof using QEMU-only multi-UDC allocator sampling executed a fixed proof command inside the guest and created a UID-0-owned marker during automatic enumeration, with KASLR and NX enabled. The issue was independently found during security research at Drivesec S.r.l. Cap the available length to the buffer size. Validate and consume the mode header and block descriptor lengths before using the page, and require the five bytes needed to access the CDL field.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 6 associated CPEs
Vendor Product Version / Range
Linux Linux 1b22cfb14142aba7742d307c4f8d7006f919308c
Linux Linux 1b22cfb14142aba7742d307c4f8d7006f919308c
Linux Linux 1b22cfb14142aba7742d307c4f8d7006f919308c
Linux Linux 1b22cfb14142aba7742d307c4f8d7006f919308c
Linux Linux 1b22cfb14142aba7742d307c4f8d7006f919308c
Linux Linux 6.5

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel involves a flaw in the SCSI core's scsi_cdl_enable() function. A target device can report a shorter length than expected, causing an unsigned subtraction to wrap. This leads to an out-of-bounds stack byte being modified during automatic scanning of a USB storage device. The issue allows stack contents to be disclosed to the target without requiring filesystem access or userspace interaction.

Detection Guidance

This vulnerability is specific to the Linux kernel's SCSI subsystem and is triggered during automatic scan of USB storage devices. Detection requires checking kernel logs for errors related to scsi_cdl_enable() or MODE SENSE operations. Use 'dmesg | grep -i scsi' or 'journalctl -k | grep -i scsi' to review kernel logs for suspicious activity.

Impact Analysis

An attacker could exploit this to read sensitive stack memory from your system. This could potentially expose confidential data or system information. The vulnerability is triggered when scanning a USB storage device that mimics an ATA device with CDL support, making it a risk during normal device enumeration.

Mitigation Strategies

Update your Linux kernel to the latest stable version that includes the fix for this issue. If immediate update is not possible, avoid connecting untrusted USB storage devices that may trigger the vulnerability during automatic scanning.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-98232. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart