0.0
NA
CVE-2026-89851
scsi: qla2xxx: Fix FCE trace enable parsing in debugfs
Description

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix FCE trace enable parsing in debugfs qla2x00_dfs_fce_write() called kstrtoul() with a NULL result pointer, so a successful parse would dereference NULL and oops. Worse, the int return value (0 on success, negative errno on failure) was assigned to the unsigned long enable flag, inverting the intended logic: a valid number was treated as "disable" while a parse failure enabled FCE. Parse the value into enable and propagate parse errors to userspace.

INFO

Published Date :

Sept. 16, 2026, 11:16 a.m.

Last Modified :

Sept. 16, 2026, 11:16 a.m.

Remotely Exploit :

No

Source :

416baaa9-dc9f-4396-8d5f-8c081fb06d67
Affected Products

The following products are affected by CVE-2026-89851 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

ID Vendor Product Action
1 Linux linux_kernel
Solution
Update Linux kernel to fix FCE trace enable parsing in debugfs.
  • Update the Linux kernel to the latest version.
  • Apply the specific patch for qla2xxx driver.
  • Ensure debugfs parsing handles NULL pointers correctly.
  • Validate integer return values for parse operations.
CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2026-89851 is associated with the following CWEs:

Common Attack Pattern Enumeration and Classification (CAPEC)

Common Attack Pattern Enumeration and Classification (CAPEC) stores attack patterns, which are descriptions of the common attributes and approaches employed by adversaries to exploit the CVE-2026-89851 weaknesses.

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2026-89851 vulnerability anywhere in the article.

The following table lists the changes that have been made to the CVE-2026-89851 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.

  • New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67

    Sep. 16, 2026

    Action Type Old Value New Value
    Added Description In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix FCE trace enable parsing in debugfs qla2x00_dfs_fce_write() called kstrtoul() with a NULL result pointer, so a successful parse would dereference NULL and oops. Worse, the int return value (0 on success, negative errno on failure) was assigned to the unsigned long enable flag, inverting the intended logic: a valid number was treated as "disable" while a parse failure enabled FCE. Parse the value into enable and propagate parse errors to userspace.
    Added Affected New affected value received. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/89xxx/CVE-2026-89851.json">CVE-2026-89851</a>
    Added Reference https://git.kernel.org/stable/c/5762d992dddaf301e7fb78f797de407116847121
    Added Reference https://git.kernel.org/stable/c/7203d4aed8f444e7376c2dee8d93577b37cf9989
    Added Reference https://git.kernel.org/stable/c/9932cbd0b49d0a5ab8378d32650ffb51604ffa35
    Added Reference https://git.kernel.org/stable/c/aac0d3cb9199121d2ce5906e06f94b793fac1052
    Added Reference https://git.kernel.org/stable/c/b0c08c08a08b6cca0e7e192bcbe0514e41fcc55f
    Added Reference https://git.kernel.org/stable/c/b7368687e3d11f51392d3c4774ec0263d5fbf31f
    Added Reference https://git.kernel.org/stable/c/eff41f50461c238bd2c5cd20672a5b53e68d493a
    Added Reference https://git.kernel.org/stable/c/f5e245164d187d1ee227140c8b2e83b67f59c1fd
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.