SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-89456

HIGH · CVSS 7 EPSS 0.14%

Source: NVD + CISA KEV + EPSS · Published 2026-09-11 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's handling of device requests in the s390 architecture, specifically related to the dasd (Direct Access Storage Device) subsystem. It can lead to incomplete data being returned to applications, as partially completed requests may be incorrectly finalized, resulting in zeroed data being delivered instead of the expected bytes. Organizations utilizing Linux on s390 systems should prioritize addressing this issue to prevent potential data integrity problems in their storage operations.

CVE
CVE-2026-89456
Severity
HIGH
CVSS
7
EPSS
0.14%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: s390/dasd: Propagate partial completion length across ERP recovery dasd_default_erp_postaction() copies the timing and device state from the finished ERP request back to the original request but drops proc_bytes. A request that was partially completed, an ESE read of a not-yet-allocated track returns fewer bytes than requested, and then recovered through the ERP chain loses its partial-completion length. __dasd_cleanup_cqr() then sees proc_bytes == 0 and completes the whole request instead of requeueing the remainder, silently returning zeroed data for the part that was never read. Carry proc_bytes over to the original request like the other per-request state.