{"id":"CVE-2026-89586","title":"kernel: ata: libata-scsi: fix DSM TRIM for sector sizes larger than 2048 bytes (CVE-2026-89586)","summary":"A flaw was found in the Linux kernel's `libata-scsi` component. This vulnerability occurs when the system attempts to perform Data Set Management (DSM) TRIM operations on storage devices with logical sector sizes exceeding 2048 bytes. Due …","severity":"medium","cvss":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","cvssSource":"vendor","cwe":"CWE-130","vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","affected":["enterprise_linux 10","enterprise_linux 6","enterprise_linux 8","enterprise_linux 9","openshift_container_platform 4"],"published":"2026-09-11","updated":"2026-09-15","sourceUpdated":"2026-09-15T10:37:44+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89586.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89586.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-89586"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2532420"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-89586"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89586"},{"url":"https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-89586.mbox"},{"url":"https://git.kernel.org/stable/c/07975b8daa3b0ab3cbc02cc48ea7bc48fadcec53"},{"url":"https://git.kernel.org/stable/c/b7b5ab2df325ffbbad7ca2debaa071e024d68cb5"},{"url":"https://git.kernel.org/stable/c/07baa310ea3224a7044b1ca84796bb37a235af1f"},{"url":"https://git.kernel.org/stable/c/977554ed91b54075fbc0bac536316b4841ef6258"},{"url":"https://git.kernel.org/stable/c/04e2befe25792f2e90097f284d7e86fc6bcfe928"},{"url":"https://git.kernel.org/stable/c/c2e3dccd6870659851eaa4c12ab16418b8e3040a"},{"url":"https://git.kernel.org/stable/c/4a4268a0b0a595bd9534cf9c7fda93775a7d8a0d"},{"url":"https://git.kernel.org/stable/c/79cce911e623c0baa0fde307ce3a434e084b881a"}],"tags":["csaf","vex","red-hat","cve.org","score-dispute"],"epss":0.00607,"epssPercentile":0.47691,"scores":{"vendor":5.5,"cna":8.2},"ingestedAt":"2026-09-14T15:23:07.451Z","slug":"CVE-2026-89586","body":"## Overview\n\nA flaw was found in the Linux kernel's `libata-scsi` component. This vulnerability occurs when the system attempts to perform Data Set Management (DSM) TRIM operations on storage devices with logical sector sizes exceeding 2048 bytes. Due to an incorrect handling of the TRIM descriptor generation, these operations are rejected. This prevents the efficient reclamation of storage space, leading to a denial of service for the TRIM functionality on affected devices.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Low · affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4 · no fix planned: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, … · updated 2026-09-15 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89586.json)\n\n**kernel: ata: libata-scsi: fix DSM TRIM for sector sizes larger than 2048 bytes** — rated Low by Red Hat. Released 2026-09-11, updated 2026-09-15.\n\nAffected:\n\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 6\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n\nNo fix planned:\n\n- Red Hat Enterprise Linux 6\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n\nNot affected:\n\n- Red Hat Enterprise Linux 7\n\n## Remediation\n\nOut of support scope","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":30.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[{"seq":203915,"id":"CVE-2026-89586","ts":1789490221070,"field":"cvss","old":"8.2","new":"5.5"},{"seq":203914,"id":"CVE-2026-89586","ts":1789490221070,"field":"severity","old":"high","new":"medium"},{"seq":197888,"id":"CVE-2026-89586","ts":1789384320821,"field":"cvss","old":"4.4","new":"8.2"},{"seq":197887,"id":"CVE-2026-89586","ts":1789384320821,"field":"severity","old":"medium","new":"high"},{"seq":183439,"id":"CVE-2026-89586","ts":1789356675373,"field":"cvss","old":"8.2","new":"4.4"},{"seq":183438,"id":"CVE-2026-89586","ts":1789356675373,"field":"severity","old":"high","new":"medium"},{"seq":153404,"id":"CVE-2026-89586","ts":1789285350377,"field":"cvss","old":null,"new":"8.2"},{"seq":153403,"id":"CVE-2026-89586","ts":1789285350377,"field":"severity","old":"none","new":"high"},{"seq":147223,"id":"CVE-2026-89586","ts":1789270202420,"field":"cvss","old":null,"new":"4.4"},{"seq":147222,"id":"CVE-2026-89586","ts":1789270202420,"field":"severity","old":"none","new":"medium"},{"seq":108976,"id":"CVE-2026-89586","ts":1789183729805,"field":"cvss","old":null,"new":"4.4"},{"seq":108975,"id":"CVE-2026-89586","ts":1789183729805,"field":"severity","old":"none","new":"medium"}]}