{"id":"CVE-2026-89458","title":"kernel: s390/dasd: Do not complete a failed ESE read as successful (CVE-2026-89458)","summary":"A flaw was found in the Linux kernel's s390/dasd component. The `dasd_int_handler()` function incorrectly marks failed Extended Sense Data (ESE) read operations as successful when processing unallocated ESE tracks. This leads to the block …","severity":"high","cvss":7,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","cvssSource":"vendor","cwe":"CWE-824","vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","affected":["enterprise_linux 10","enterprise_linux 9","openshift_container_platform 4"],"published":"2026-09-11","updated":"2026-09-14","sourceUpdated":"2026-09-14T17:36:45+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89458.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89458.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-89458"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2532050"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-89458"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89458"},{"url":"https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-89458.mbox"},{"url":"https://git.kernel.org/stable/c/8cb96cffceead3cbd0541154d7ecc5e6474edda1"},{"url":"https://git.kernel.org/stable/c/77168af195d04b34c6de62b874624e74d64cef8d"},{"url":"https://git.kernel.org/stable/c/921ff697bb6f7067059793becf8b2d00de71ce41"},{"url":"https://git.kernel.org/stable/c/55f4df40178cdfede0d7ae848fbab00efa9b95c1"},{"url":"https://git.kernel.org/stable/c/c9adf8399732306dfc97b3adb4778038743e3f5e"},{"url":"https://git.kernel.org/stable/c/52b331c99baac653ca794bd8487c8ec4de8db203"},{"url":"https://git.kernel.org/stable/c/b0d94dd6e82df396e2254c8b0f25eff7d19c2e7f"},{"url":"https://git.kernel.org/stable/c/cddb447c62466f3076938ce120028d7b591f9f37"}],"tags":["csaf","vex","red-hat","cve.org"],"epss":0.00176,"epssPercentile":0.07422,"ingestedAt":"2026-09-14T15:23:07.453Z","slug":"CVE-2026-89458","body":"## Overview\n\nA flaw was found in the Linux kernel's s390/dasd component. The `dasd_int_handler()` function incorrectly marks failed Extended Sense Data (ESE) read operations as successful when processing unallocated ESE tracks. This leads to the block layer receiving stale or uninitialized memory instead of properly zeroed memory. A local attacker could exploit this vulnerability to potentially gain access to sensitive information, resulting in information disclosure.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4 · no fix planned: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4 · updated 2026-09-14 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89458.json)\n\n**kernel: s390/dasd: Do not complete a failed ESE read as successful** — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-14.\n\nAffected:\n\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n\nNo fix planned:\n\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n\nNot affected:\n\n- Red Hat Enterprise Linux 6\n- Red Hat Enterprise Linux 7\n- Red Hat Enterprise Linux 8\n- Red Hat OpenShift Container Platform 4\n\n## Remediation\n\nAffected","depth":"twilight","depthScore":39,"depthScoreParts":{"impact":38.5,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":204229,"id":"CVE-2026-89458","ts":1789490240413,"field":"cvss","old":null,"new":"7"},{"seq":204228,"id":"CVE-2026-89458","ts":1789490240413,"field":"severity","old":"none","new":"high"},{"seq":147810,"id":"CVE-2026-89458","ts":1789270212379,"field":"cvss","old":null,"new":"4.7"},{"seq":147809,"id":"CVE-2026-89458","ts":1789270212379,"field":"severity","old":"none","new":"medium"},{"seq":109568,"id":"CVE-2026-89458","ts":1789183732447,"field":"cvss","old":null,"new":"4.7"},{"seq":109567,"id":"CVE-2026-89458","ts":1789183732447,"field":"severity","old":"none","new":"medium"}]}