# CVE-2026-89456

## Summary

- **CVE ID:** CVE-2026-89456
- **Severity:** HIGH
- **CVSS Score:** 7 (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** N/A
- **Published:** Sep 11, 2026
- **Last Modified:** Sep 14, 2026

## Description

In the Linux kernel, the following vulnerability has been resolved:

s390/dasd: Propagate partial completion length across ERP recovery

dasd_default_erp_postaction() copies the timing and device state from
the finished ERP request back to the original request but drops
proc_bytes. A request that was partially completed, an ESE read of a
not-yet-allocated track returns fewer bytes than requested, and then
recovered through the ERP chain loses its partial-completion length.
__dasd_cleanup_cqr() then sees proc_bytes == 0 and completes the whole
request instead of requeueing the remainder, silently returning zeroed
data for the part that was never read.

Carry proc_bytes over to the original request like the other
per-request state.

## Affected Products

- Linux — Linux (5e6bdd37c5526ef01326df5dabb93011ee89237e)
- Linux — Linux (fbbacd0dcbc3ae9398c569dbea96ae4b5ad97e04)
- Linux — Linux (5f7c9989f11305aaa43e0f4378f4f070022a9f2b)
- Linux — Linux (5.4.26)
- Linux — Linux (5.5.10)
- Linux — Linux (5.6)
- Linux — Linux (0)
- Linux — Linux (6.12.109)
- Linux — Linux (6.18.50)
- Linux — Linux (7.2.4)
- Linux — Linux (7.3-rc1)
- Linux — Linux (5.10.270)
- Linux — Linux (5.15.221)
- Linux — Linux (6.1.188)
- Linux — Linux (6.6.157)

## References

- [CNA](https://git.kernel.org/stable/c/d6b8778b1b82aa3a8dbf8612080f635b834bd16b)
- [CNA](https://git.kernel.org/stable/c/ceafb262475ac6cb3a7d07b1102608be2b216b99)
- [CNA](https://git.kernel.org/stable/c/15ec03452c18e8d288e519837d21b308300d74b2)
- [CNA](https://git.kernel.org/stable/c/6fb5ba2e7e43173a3761e46f091070a8185efa14)
- [CNA](https://git.kernel.org/stable/c/9e063165d3fe58db2a517717b830f17e82d03467)
- [CNA](https://git.kernel.org/stable/c/6b0954c8a259da1e4aa745989f82723947acfb46)
- [CNA](https://git.kernel.org/stable/c/d0a2f97d8c97134aa7f6a191940b7bab4bb42f5f)
- [CNA](https://git.kernel.org/stable/c/f735b9710f0c8fe72c1060103e865f4ae678190b)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.14%
- **EPSS Percentile:** 4.2

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._