PT-2026-94761 · Linux · Linux Kernel
CVE-2026-90413
·
Published
2026-09-17
·
Updated
2026-09-28
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 7.2.0-rc4
Description
An issue exists in the IB/isert component where the system fails to compare the actual bytes received in the login buffer against the length declared in the login Protocol Data Unit (PDU) Basic Header Segment (BHS). An initiator can declare a length greater than the data actually sent, leading to a slab-out-of-bounds read when the system attempts to copy the buffer. This occurs because the
login->req buf is a fixed 8192-byte allocation, and the system reads the declared length back from this buffer without validation.The issue is triggered in the following functions:
iscsi target locate portal()for the first PDU.iscsi decode text input()for subsequent PDUs.
The vulnerable variable is
dlength, which is used to determine the payload length for the kmemdup nul() function. This allows an attacker to read memory beyond the allocated buffer before authentication is completed.Recommendations
Update the Linux kernel to version 7.2.0-rc4 or later.
As a temporary mitigation, restrict access to the iSER (iSCSI Extensions for RDMA) target services to trusted initiators only.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel