PT-2026-94762 · Linux · Linux Kernel
CVE-2026-90414
·
Published
2026-09-17
·
Updated
2026-09-28
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An issue exists in the iSER (iSCSI Extensions for RDMA) implementation where the
isert recv done() function processes received Protocol Data Units (PDUs) without verifying if the declared data length matches the actual number of bytes received in the receive descriptor (wc->byte len). This allows a malicious initiator to declare a data segment larger than the actual data sent, leading to an out-of-bounds read of the receive buffer.Technical details include:
- Vulnerable functions:
isert handle iscsi dataout()andisert handle scsi cmd()usesg copy from buffer()to copy data based on the initiator-declared length without validation. - The issue is exacerbated because the
TargetRecvDataSegmentLengthparameter is adopted from the initiator without being clamped to the fixed receive descriptor size (ISER RX SIZE). - In certain paths, this can lead to heap contents beyond the descriptor being written to the backing store via a SCSI WRITE operation.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel