PT-2026-106686 · Linux · Linux

CVE-2026-98357

·

Published

2026-10-06

·

Updated

2026-10-06

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
IB/isert: wait for deferred control PDU completions before releasing the connection
isert send done() hands ISTATE SEND TASKMGTRSP, ISTATE SEND REJECT and ISTATE SEND TEXTRSP completions off to isert comp wq and returns. The work item then runs isert completion put() -> isert put cmd(), which reads isert conn->conn and takes conn->cmd lock.
Nothing orders that work item against teardown. isert wait conn() queues isert release work, which frees isert conn, and iscsit close connection() frees the iscsit conn right after it returns, so the queued work can run against freed memory.
Count the deferred control PDU completions per connection and let isert wait conn() wait for them before the release work is queued.
ISTATE SEND LOGOUTRSP is deliberately not counted: that branch runs iscsit logout post handler(), which ends up waiting for conn->conn wait comp, and that completion is only sent by iscsit close connection() after it has called iscsit wait conn(). Waiting for it here would deadlock. Its wait stays the existing isert wait4logout().
The splat below is from a kernel with tracing printk()s and an msleep(200) injected into isert do control comp() to widen the window:
BUG: KASAN: slab-use-after-free in isert put cmd+0x53d/0x620 Read of size 8 at addr ffff8881054f1038 by task kworker/u17:1/182
CPU: 0 UID: 0 PID: 182 Comm: kworker/u17:1 Tainted: G B 7.2.0-rc5-TWIDE-gb8babf08acc7 #1 PREEMPT(lazy) Tainted: [B]=BAD PAGE Hardware name: QEMU Ubuntu 24.04 PC v2 (i440FX + PIIX, arch caps fix, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014 Workqueue: isert comp wq isert do control comp Call Trace: dump stack lvl+0x53/0x70 print report+0xd0/0x630 ? pfx raw spin lock irqsave+0x10/0x10 ? raw spin unlock irqrestore+0x3e/0x70 ? isert put cmd+0x53d/0x620 kasan report+0xce/0x100 ? isert put cmd+0x53d/0x620 isert put cmd+0x53d/0x620 ? isert completion put+0x305/0x330 ? isert do control comp+0x2ef/0x310 process one work+0x633/0x1030 ? assign work+0x11d/0x370 worker thread+0x45b/0xd10 ? pfx worker thread+0x10/0x10 ? pfx worker thread+0x10/0x10 kthread+0x2c6/0x3b0 ? recalc sigpending+0x15c/0x1e0 ? pfx kthread+0x10/0x10 ret from fork+0x36e/0x5a0 ? pfx ret from fork+0x10/0x10 ? switch to+0x572/0xdd0 ? pfx kthread+0x10/0x10 ret from fork asm+0x1a/0x30
Allocated by task 48: kasan save stack+0x33/0x60 kasan save track+0x14/0x30 kasan kmalloc+0x8f/0xa0 kmalloc cache noprof+0x158/0x370 isert cma handler+0x1e3/0x2ae0 cma cm event handler+0x3e/0x240 cma ib req handler+0x17d9/0x4490 cm process work+0x41/0x330 cm work handler+0x5727/0xc160 process one work+0x633/0x1030 worker thread+0x45b/0xd10 kthread+0x2c6/0x3b0 ret from fork+0x36e/0x5a0 ret from fork asm+0x1a/0x30
Freed by task 184: kasan save stack+0x33/0x60 kasan save track+0x14/0x30 kasan save free info+0x3b/0x60 kasan slab free+0x43/0x70 kfree+0x121/0x380 iscsit close connection+0x7cf/0x1e60 iscsit take action for connection exit+0x1b6/0x360 iscsi target tx thread+0x472/0x690 kthread+0x2c6/0x3b0 ret from fork+0x36e/0x5a0 ret from fork asm+0x1a/0x30
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-98357

Affected Products

Linux