PT-2026-106687 · Linux · Linux
CVE-2026-98358
·
Published
2026-10-06
·
Updated
2026-10-06
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
IB/iser: reject a remote invalidation of an unregistered direction
A write command whose data is sent entirely as immediate data is not
registered. iser reg mem fastreg() takes the DMA key path and leaves
rdma reg[ISER DIR OUT].desc at NULL, while iser dma map task data() has
already set dir[ISER DIR OUT].
iser check remote inv() looks at dir[] alone and hands the descriptor to
iser inv desc(), which reads desc->sig protected. A target that answers
such a command with IB WR SEND WITH INV faults the initiator.
Leaving those commands unregistered is deliberate.
The same function already terminates the connection when a target sends
a remote invalidation the initiator did not ask for. A target that
invalidates a direction that was never registered is in the same class,
so give it the same answer.
Oops: general protection fault, probably for non-canonical address 0xdffffc0000000004: 0000 [#1] SMP KASAN NOPTI
KASAN: null-ptr-deref in range [0x0000000000000020-0x0000000000000027]
CPU: 0 UID: 0 PID: 40 Comm: kworker/u8:2 Not tainted 7.2.0-rc5-ISERHOST-gf5098b6bae76-dirty #3 PREEMPT(lazy)
Hardware name: QEMU Ubuntu 24.04 PC v2 (i440FX + PIIX, arch caps fix, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
Workqueue: rxe wq do work
RIP: 0010:iser task rsp+0x6d6/0xec0
Code: 48 c1 ea 03 80 3c 02 00 0f 85 ba 06 00 00 48 8b 9b 78 01 00 00 48 b8 00 00 00 00 00 fc ff df 48 8d 7b 20 48 89 fa 48 c1 ea 03 <0f> b6 04 02 84 c0 74 06 0f 8e 76 06 00 00 80 7b 20 00 0f 84 3d 04
RSP: 0018:ffff88811b008db8 EFLAGS: 00010202
RAX: dffffc0000000000 RBX: 0000000000000000 RCX: 0000000000001848
RDX: 0000000000000004 RSI: 1ffff11021587b12 RDI: 0000000000000020
RBP: ffff88810adc1ae4 R08: ffff888109b7f860 R09: ffffffff90a922c0
R10: ffff88810adc1a1c R11: 000000000000003c R12: ffff888109b7f800
R13: ffff88810adc1acc R14: ffff888109b7f820 R15: 0000000000000000
FS: 0000000000000000(0000) GS:ffff88818a676000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00000000005afe2b CR3: 000000010af23005 CR4: 0000000000770ef0
PKRU: 55555554
Call Trace:
ib process cq+0xe1/0x390
ib poll handler+0x6e/0x200
irq poll softirq+0x1df/0x480
? clockevents program event+0x2ba/0x860
? pfx irq poll softirq+0x10/0x10
handle softirqs+0x18e/0x590
? pfx handle softirqs+0x10/0x10
? hrtimer rearm deferred+0x156/0x450
do softirq+0x3b/0x60
local bh enable ip+0x61/0x70
alloc skb+0x732/0x890
? raw spin lock irqsave+0x85/0xe0
? pfx alloc skb+0x10/0x10
? raw read unlock irqrestore+0x16/0x50
rxe init packet+0x16b/0x4f0
prepare ack packet+0xb8/0x830
rxe receiver+0x499/0x9980
? pfx rxe receiver+0x10/0x10
? rxe completer+0x29e5/0x38c0
? hrtimer start range ns common+0x75f/0x1730
? hrtimer start range ns+0xa6/0x2c0
? pfx raw spin lock irqsave+0x10/0x10
? pfx rxe receiver+0x10/0x10
do work+0x144/0x470
process one work+0x633/0x1030
? assign work+0x11d/0x370
worker thread+0x45b/0xd10
? pfx worker thread+0x10/0x10
kthread+0x2c6/0x3b0
? recalc sigpending+0x15c/0x1e0
? pfx kthread+0x10/0x10
ret from fork+0x36e/0x5a0
? pfx ret from fork+0x10/0x10
? switch to+0x572/0xdd0
? pfx kthread+0x10/0x10
ret from fork asm+0x1a/0x30
Modules linked in:
---[ end trace 0000000000000000 ]---
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux