{"id":"CVE-2026-89456","title":"kernel: s390/dasd: Propagate partial completion length across ERP recovery (CVE-2026-89456)","summary":"A flaw was found in the Linux kernel. Specifically, within the s390/dasd component, an issue exists during error recovery for disk read operations. When a request is partially completed and then recovered, the system fails to correctly pro…","severity":"high","cvss":7,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","cvssSource":"vendor","cwe":"CWE-908","vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","affected":["enterprise_linux 10","enterprise_linux 9","openshift_container_platform 4"],"published":"2026-09-11","updated":"2026-09-17","sourceUpdated":"2026-09-17T19:48:29+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89456.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89456.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-89456"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2532243"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-89456"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89456"},{"url":"https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-89456.mbox"},{"url":"https://git.kernel.org/stable/c/9e063165d3fe58db2a517717b830f17e82d03467"},{"url":"https://git.kernel.org/stable/c/6b0954c8a259da1e4aa745989f82723947acfb46"},{"url":"https://git.kernel.org/stable/c/d0a2f97d8c97134aa7f6a191940b7bab4bb42f5f"},{"url":"https://git.kernel.org/stable/c/f735b9710f0c8fe72c1060103e865f4ae678190b"},{"url":"https://git.kernel.org/stable/c/d6b8778b1b82aa3a8dbf8612080f635b834bd16b"},{"url":"https://git.kernel.org/stable/c/ceafb262475ac6cb3a7d07b1102608be2b216b99"},{"url":"https://git.kernel.org/stable/c/15ec03452c18e8d288e519837d21b308300d74b2"},{"url":"https://git.kernel.org/stable/c/6fb5ba2e7e43173a3761e46f091070a8185efa14"}],"tags":["csaf","vex","red-hat","cve.org"],"epss":0.00145,"epssPercentile":0.04147,"ingestedAt":"2026-09-14T15:23:07.453Z","slug":"CVE-2026-89456","body":"## Overview\n\nA flaw was found in the Linux kernel. Specifically, within the s390/dasd component, an issue exists during error recovery for disk read operations. When a request is partially completed and then recovered, the system fails to correctly propagate the length of the processed data. This can lead to the kernel silently returning zeroed data for the unread portion of a request, potentially resulting in information disclosure to a local attacker.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4 · no fix planned: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4 · updated 2026-09-17 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89456.json)\n\n**kernel: s390/dasd: Propagate partial completion length across ERP recovery** — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-17.\n\nAffected:\n\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n\nNo fix planned:\n\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n\nNot affected:\n\n- Red Hat Enterprise Linux 6\n- Red Hat Enterprise Linux 7\n- Red Hat Enterprise Linux 8\n- Red Hat OpenShift Container Platform 4\n\n## Remediation\n\nAffected","depth":"twilight","depthScore":39,"depthScoreParts":{"impact":38.5,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":198048,"id":"CVE-2026-89456","ts":1789384321540,"field":"cvss","old":"5.2","new":"7"},{"seq":198047,"id":"CVE-2026-89456","ts":1789384321540,"field":"severity","old":"medium","new":"high"},{"seq":183540,"id":"CVE-2026-89456","ts":1789356675805,"field":"cvss","old":"7","new":"5.2"},{"seq":183539,"id":"CVE-2026-89456","ts":1789356675805,"field":"severity","old":"high","new":"medium"},{"seq":153236,"id":"CVE-2026-89456","ts":1789285349672,"field":"cvss","old":null,"new":"7"},{"seq":153235,"id":"CVE-2026-89456","ts":1789285349672,"field":"severity","old":"none","new":"high"},{"seq":147504,"id":"CVE-2026-89456","ts":1789270211168,"field":"cvss","old":null,"new":"5.2"},{"seq":147503,"id":"CVE-2026-89456","ts":1789270211168,"field":"severity","old":"none","new":"medium"},{"seq":109264,"id":"CVE-2026-89456","ts":1789183731197,"field":"cvss","old":null,"new":"5.2"},{"seq":109263,"id":"CVE-2026-89456","ts":1789183731197,"field":"severity","old":"none","new":"medium"}]}