Junglewise Threat Intelligence

CVE-2023-54184: Linux kernel iSCSI target use-after-free in session cleanup

CVE-2023-54184 · Severity: critical · CVSS 9.8 · Published 2025-12-30

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's iSCSI target implementation contains a use-after-free vulnerability in session cleanup logic. When an iSCSI session expires (via Time2Retain timer) with error recovery enabled, recovery commands are freed after the session object itself is destroyed, causing a kernel null pointer dereference. This can crash the kernel or allow a local attacker with network access to the iSCSI target to trigger a denial of service.

Technical details

The vulnerability is a use-after-free in the iSCSI target implementation (iscsit). When closing a session with ErrorRecoveryLevel==2, recovery commands are freed via iscsit_free_connection_recovery_entries() after the session has already been deregistered by transport_deregister_session(). This causes a null pointer dereference in sbitmap_queue_clear() when target_release_cmd_kref() attempts to release freed command structures. The fix moves the recovery entry cleanup to occur before session deregistration. The vulnerability is triggered when the Time2Retain timer expires during session cleanup, requiring network-reachable iSCSI target access but no special authentication.

Affected products

  • Linux Linux kernel multiple versions up to and including Linux 5.19 and earlier stable series

Timeline

  • 2025-12-30: disclosed: CVE published
  • 2023-03-18: patched: Fix commit d8990b5a4d065f38f35d69bcd627ec5a7f8330ca
  • 2023-05-24: other: Backported to stable kernel trees

References

Related threats