PT-2026-94761 · Linux · Linux Kernel

CVE-2026-90413

·

Published

2026-09-17

·

Updated

2026-09-28

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 7.2.0-rc4
Description An issue exists in the IB/isert component where the system fails to compare the actual bytes received in the login buffer against the length declared in the login Protocol Data Unit (PDU) Basic Header Segment (BHS). An initiator can declare a length greater than the data actually sent, leading to a slab-out-of-bounds read when the system attempts to copy the buffer. This occurs because the login->req buf is a fixed 8192-byte allocation, and the system reads the declared length back from this buffer without validation.
The issue is triggered in the following functions:
  • iscsi target locate portal() for the first PDU.
  • iscsi decode text input() for subsequent PDUs.
The vulnerable variable is dlength, which is used to determine the payload length for the kmemdup nul() function. This allows an attacker to read memory beyond the allocated buffer before authentication is completed.
Recommendations Update the Linux kernel to version 7.2.0-rc4 or later. As a temporary mitigation, restrict access to the iSER (iSCSI Extensions for RDMA) target services to trusted initiators only.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-101978
CVE-2026-90413
OPENSUSE-SU-2026:11893-1

Affected Products

Linux Kernel