UNKNOWN NVD
CVE-2026-89851
In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix FCE trace enable parsing in debugfs qla2x00_dfs_fce_write() called kstr
In the Linux kernel, the following vulnerability has been resolved:
scsi: qla2xxx: Fix FCE trace enable parsing in debugfs
qla2x00_dfs_fce_write() called kstrtoul() with a NULL result pointer,
so a successful parse would dereference NULL and oops. Worse, the int
return value (0 on success, negative errno on failure) was assigned to
the unsigned long enable flag, inverting the intended logic: a valid
number was treated as "disable" while a parse failure enabled FCE.
Parse the value into enable and propagate parse errors to userspace.
References
- https://git.kernel.org/stable/c/5762d992dddaf301e7fb78f797de407116847121
- https://git.kernel.org/stable/c/7203d4aed8f444e7376c2dee8d93577b37cf9989
- https://git.kernel.org/stable/c/9932cbd0b49d0a5ab8378d32650ffb51604ffa35
- https://git.kernel.org/stable/c/aac0d3cb9199121d2ce5906e06f94b793fac1052
- https://git.kernel.org/stable/c/b0c08c08a08b6cca0e7e192bcbe0514e41fcc55f
This unknown severity vulnerability was published on 2026-09-16 via NVD.
vulnfeed aggregates 14391 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.