Executive brief
A vulnerability in the Linux kernel's iSCSI Extensions for RDMA (iSER) target driver could allow an unauthenticated remote attacker to crash the system. By sending a specially crafted login request that is shorter than expected, an attacker can trigger a memory error that leads to a kernel panic. This results in a denial-of-service condition, potentially disrupting storage services and business operations.
Technical details
An integer underflow vulnerability exists in drivers/infiniband/ulp/isert/ib_isert.c within the isert_login_recv_done() function. The code calculates the login request payload length by subtracting ISER_HEADERS_LEN (76 bytes) from the received byte length without verifying that the received length is at least 76 bytes. If a remote initiator sends a PDU shorter than 76 bytes, the resulting signed integer (login_req_len) becomes negative. This negative value is subsequently used in a min() comparison and passed to memcpy(), where it is sign-extended to a massive size_t value, causing a massive out-of-bounds copy and a kernel crash. This occurs during the login phase before iSCSI authentication, making it exploitable by unauthenticated remote attackers. The fix introduces a check to reject PDUs shorter than ISER_HEADERS_LEN.
Affected products
- Linux Linux Kernel b8d26b3be8b3 to 75ee6e4aa096aa9e7b2dd5c8ff98356e30aceefb
Timeline
- 2026-06-02: disclosed: Vulnerability reported and patch submitted by Michael Bommarito
- 2026-06-19: patched: Patch committed to stable tree by Greg Kroah-Hartman
- 2026-06-25: advisory: CVE-2026-53176 published
References
- https://git.kernel.org/stable/c/1ca40b243277c9e88be5e00bd3e083f71aefb93e
- https://git.kernel.org/stable/c/29e7b925ae6df64894e82ab6419994dc25580a8a
- https://git.kernel.org/stable/c/75ee6e4aa096aa9e7b2dd5c8ff98356e30aceefb
- https://git.kernel.org/stable/c/bd22740d7f14cb1c0289444cfd2c8d2938667c1d
- https://git.kernel.org/stable/c/c1234229399f4af12c553b1b0ffd978eeba65548
- https://git.kernel.org/stable/c/c5584e089b5af7b3bf8bd5e8ca0560cbf32b0a47
- https://git.kernel.org/stable/c/df422fd273c96c2ee5beb80fc21adc8c70c29260