Executive brief
A vulnerability in the Linux kernel's iSCSI subsystem can cause a complete system crash (kernel panic). This occurs when the system fails to allocate memory during the setup of certain storage network connections, leading to an invalid memory access during the subsequent cleanup process. An attacker with local access could potentially trigger this condition to disrupt system availability.
Technical details
A NULL pointer dereference exists in drivers/scsi/libiscsi.c within the iscsi_conn_setup function. The vulnerability is triggered when an ib_fast_reg_mr allocation fails during iSER (iSCSI Extensions for RDMA) setup. Even when allocation fails (dd_size == 0), the kernel unconditionally initializes iscsi_conn->dd_data, leading to an invalid pointer dereference during the connection teardown phase (iscsi_stop_conn). This results in a kernel panic. The fix introduces a check to ensure dd_data is only initialized if memory was actually allocated. This issue affects multiple stable branches of the Linux kernel.
Affected products
- Linux Linux Kernel 2.6.27 to 5.4.297, 5.5 to 5.10.241, 5.11 to 5.15.190, 5.16 to 6.1.149, 6.2 to 6.6.103, 6.7 to 6.12.43, 6.13 to 6.15.11, 6.16 to 6.16.2
Timeline
- 2025-06-27: other: Patch submitted by developer
- 2025-09-04: disclosed: CVE published
- 2025-08-20: patched: Patch committed to stable trees
References
- https://git.kernel.org/stable/c/2b242ea14386a510010eabfbfc3ce81a101f3802
- https://git.kernel.org/stable/c/35782c32528d82aa21f84cb5ceb2abd3526a8159
- https://git.kernel.org/stable/c/3ea3a256ed81f95ab0f3281a0e234b01a9cae605
- https://git.kernel.org/stable/c/66a373f50b4249d57f5a88c7be9676f9d5884865
- https://git.kernel.org/stable/c/9ea6d961566c7d762ed0204b06db05756fdda3b6
- https://git.kernel.org/stable/c/a145c269dc5380c063a20a0db7e6df2995962e9d
- https://git.kernel.org/stable/c/a33d42b7fc24fe03f239fbb0880dd5b4b4b97c19