Junglewise Threat Intelligence

CVE-2026-53176: Linux Kernel denial of service in iSER target driver

CVE-2026-53176 · Severity: info · CVSS 7.5 · Published 2026-06-25

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's iSCSI Extensions for RDMA (iSER) target driver could allow an unauthenticated remote attacker to crash the system. By sending a specially crafted login request that is shorter than expected, an attacker can trigger a memory error that leads to a kernel panic. This results in a denial-of-service condition, potentially disrupting storage services and business operations.

Technical details

An integer underflow vulnerability exists in drivers/infiniband/ulp/isert/ib_isert.c within the isert_login_recv_done() function. The code calculates the login request payload length by subtracting ISER_HEADERS_LEN (76 bytes) from the received byte length without verifying that the received length is at least 76 bytes. If a remote initiator sends a PDU shorter than 76 bytes, the resulting signed integer (login_req_len) becomes negative. This negative value is subsequently used in a min() comparison and passed to memcpy(), where it is sign-extended to a massive size_t value, causing a massive out-of-bounds copy and a kernel crash. This occurs during the login phase before iSCSI authentication, making it exploitable by unauthenticated remote attackers. The fix introduces a check to reject PDUs shorter than ISER_HEADERS_LEN.

Affected products

  • Linux Linux Kernel b8d26b3be8b3 to 75ee6e4aa096aa9e7b2dd5c8ff98356e30aceefb

Timeline

  • 2026-06-02: disclosed: Vulnerability reported and patch submitted by Michael Bommarito
  • 2026-06-19: patched: Patch committed to stable tree by Greg Kroah-Hartman
  • 2026-06-25: advisory: CVE-2026-53176 published

References

Related threats