PT-2026-94762 · Linux · Linux Kernel

CVE-2026-90414

·

Published

2026-09-17

·

Updated

2026-09-28

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the iSER (iSCSI Extensions for RDMA) implementation where the isert recv done() function processes received Protocol Data Units (PDUs) without verifying if the declared data length matches the actual number of bytes received in the receive descriptor (wc->byte len). This allows a malicious initiator to declare a data segment larger than the actual data sent, leading to an out-of-bounds read of the receive buffer.
Technical details include:
  • Vulnerable functions: isert handle iscsi dataout() and isert handle scsi cmd() use sg copy from buffer() to copy data based on the initiator-declared length without validation.
  • The issue is exacerbated because the TargetRecvDataSegmentLength parameter is adopted from the initiator without being clamped to the fixed receive descriptor size (ISER RX SIZE).
  • In certain paths, this can lead to heap contents beyond the descriptor being written to the backing store via a SCSI WRITE operation.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-101966
CVE-2026-90414
OPENSUSE-SU-2026:11893-1

Affected Products

Linux Kernel