PT-2026-106687 · Linux · Linux

CVE-2026-98358

·

Published

2026-10-06

·

Updated

2026-10-06

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
IB/iser: reject a remote invalidation of an unregistered direction
A write command whose data is sent entirely as immediate data is not registered. iser reg mem fastreg() takes the DMA key path and leaves rdma reg[ISER DIR OUT].desc at NULL, while iser dma map task data() has already set dir[ISER DIR OUT].
iser check remote inv() looks at dir[] alone and hands the descriptor to iser inv desc(), which reads desc->sig protected. A target that answers such a command with IB WR SEND WITH INV faults the initiator. Leaving those commands unregistered is deliberate.
The same function already terminates the connection when a target sends a remote invalidation the initiator did not ask for. A target that invalidates a direction that was never registered is in the same class, so give it the same answer.
Oops: general protection fault, probably for non-canonical address 0xdffffc0000000004: 0000 [#1] SMP KASAN NOPTI KASAN: null-ptr-deref in range [0x0000000000000020-0x0000000000000027] CPU: 0 UID: 0 PID: 40 Comm: kworker/u8:2 Not tainted 7.2.0-rc5-ISERHOST-gf5098b6bae76-dirty #3 PREEMPT(lazy) Hardware name: QEMU Ubuntu 24.04 PC v2 (i440FX + PIIX, arch caps fix, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014 Workqueue: rxe wq do work RIP: 0010:iser task rsp+0x6d6/0xec0 Code: 48 c1 ea 03 80 3c 02 00 0f 85 ba 06 00 00 48 8b 9b 78 01 00 00 48 b8 00 00 00 00 00 fc ff df 48 8d 7b 20 48 89 fa 48 c1 ea 03 <0f> b6 04 02 84 c0 74 06 0f 8e 76 06 00 00 80 7b 20 00 0f 84 3d 04 RSP: 0018:ffff88811b008db8 EFLAGS: 00010202 RAX: dffffc0000000000 RBX: 0000000000000000 RCX: 0000000000001848 RDX: 0000000000000004 RSI: 1ffff11021587b12 RDI: 0000000000000020 RBP: ffff88810adc1ae4 R08: ffff888109b7f860 R09: ffffffff90a922c0 R10: ffff88810adc1a1c R11: 000000000000003c R12: ffff888109b7f800 R13: ffff88810adc1acc R14: ffff888109b7f820 R15: 0000000000000000 FS: 0000000000000000(0000) GS:ffff88818a676000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00000000005afe2b CR3: 000000010af23005 CR4: 0000000000770ef0 PKRU: 55555554 Call Trace: ib process cq+0xe1/0x390 ib poll handler+0x6e/0x200 irq poll softirq+0x1df/0x480 ? clockevents program event+0x2ba/0x860 ? pfx irq poll softirq+0x10/0x10 handle softirqs+0x18e/0x590 ? pfx handle softirqs+0x10/0x10 ? hrtimer rearm deferred+0x156/0x450 do softirq+0x3b/0x60 local bh enable ip+0x61/0x70 alloc skb+0x732/0x890 ? raw spin lock irqsave+0x85/0xe0 ? pfx alloc skb+0x10/0x10 ? raw read unlock irqrestore+0x16/0x50 rxe init packet+0x16b/0x4f0 prepare ack packet+0xb8/0x830 rxe receiver+0x499/0x9980 ? pfx rxe receiver+0x10/0x10 ? rxe completer+0x29e5/0x38c0 ? hrtimer start range ns common+0x75f/0x1730 ? hrtimer start range ns+0xa6/0x2c0 ? pfx raw spin lock irqsave+0x10/0x10 ? pfx rxe receiver+0x10/0x10 do work+0x144/0x470 process one work+0x633/0x1030 ? assign work+0x11d/0x370 worker thread+0x45b/0xd10 ? pfx worker thread+0x10/0x10 kthread+0x2c6/0x3b0 ? recalc sigpending+0x15c/0x1e0 ? pfx kthread+0x10/0x10 ret from fork+0x36e/0x5a0 ? pfx ret from fork+0x10/0x10 ? switch to+0x572/0xdd0 ? pfx kthread+0x10/0x10 ret from fork asm+0x1a/0x30 Modules linked in: ---[ end trace 0000000000000000 ]---
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-98358

Affected Products

Linux