PT-2026-106686 · Linux · Linux
CVE-2026-98357
·
Published
2026-10-06
·
Updated
2026-10-06
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
IB/isert: wait for deferred control PDU completions before releasing the connection
isert send done() hands ISTATE SEND TASKMGTRSP, ISTATE SEND REJECT and
ISTATE SEND TEXTRSP completions off to isert comp wq and returns. The work
item then runs isert completion put() -> isert put cmd(), which reads
isert conn->conn and takes conn->cmd lock.
Nothing orders that work item against teardown. isert wait conn() queues
isert release work, which frees isert conn, and iscsit close connection()
frees the iscsit conn right after it returns, so the queued work can run
against freed memory.
Count the deferred control PDU completions per connection and let
isert wait conn() wait for them before the release work is queued.
ISTATE SEND LOGOUTRSP is deliberately not counted: that branch runs
iscsit logout post handler(), which ends up waiting for
conn->conn wait comp, and that completion is only sent by
iscsit close connection() after it has called iscsit wait conn().
Waiting for it here would deadlock. Its wait stays the existing
isert wait4logout().
The splat below is from a kernel with tracing printk()s and an msleep(200)
injected into isert do control comp() to widen the window:
BUG: KASAN: slab-use-after-free in isert put cmd+0x53d/0x620
Read of size 8 at addr ffff8881054f1038 by task kworker/u17:1/182
CPU: 0 UID: 0 PID: 182 Comm: kworker/u17:1 Tainted: G B 7.2.0-rc5-TWIDE-gb8babf08acc7 #1 PREEMPT(lazy)
Tainted: [B]=BAD PAGE
Hardware name: QEMU Ubuntu 24.04 PC v2 (i440FX + PIIX, arch caps fix, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
Workqueue: isert comp wq isert do control comp
Call Trace:
dump stack lvl+0x53/0x70
print report+0xd0/0x630
? pfx raw spin lock irqsave+0x10/0x10
? raw spin unlock irqrestore+0x3e/0x70
? isert put cmd+0x53d/0x620
kasan report+0xce/0x100
? isert put cmd+0x53d/0x620
isert put cmd+0x53d/0x620
? isert completion put+0x305/0x330
? isert do control comp+0x2ef/0x310
process one work+0x633/0x1030
? assign work+0x11d/0x370
worker thread+0x45b/0xd10
? pfx worker thread+0x10/0x10
? pfx worker thread+0x10/0x10
kthread+0x2c6/0x3b0
? recalc sigpending+0x15c/0x1e0
? pfx kthread+0x10/0x10
ret from fork+0x36e/0x5a0
? pfx ret from fork+0x10/0x10
? switch to+0x572/0xdd0
? pfx kthread+0x10/0x10
ret from fork asm+0x1a/0x30
Allocated by task 48:
kasan save stack+0x33/0x60
kasan save track+0x14/0x30
kasan kmalloc+0x8f/0xa0
kmalloc cache noprof+0x158/0x370
isert cma handler+0x1e3/0x2ae0
cma cm event handler+0x3e/0x240
cma ib req handler+0x17d9/0x4490
cm process work+0x41/0x330
cm work handler+0x5727/0xc160
process one work+0x633/0x1030
worker thread+0x45b/0xd10
kthread+0x2c6/0x3b0
ret from fork+0x36e/0x5a0
ret from fork asm+0x1a/0x30
Freed by task 184:
kasan save stack+0x33/0x60
kasan save track+0x14/0x30
kasan save free info+0x3b/0x60
kasan slab free+0x43/0x70
kfree+0x121/0x380
iscsit close connection+0x7cf/0x1e60
iscsit take action for connection exit+0x1b6/0x360
iscsi target tx thread+0x472/0x690
kthread+0x2c6/0x3b0
ret from fork+0x36e/0x5a0
ret from fork asm+0x1a/0x30
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux