Executive brief
A vulnerability was identified in the Linux kernel's iSCSI target component, which manages storage connections over a network. An attacker could potentially cause a system crash or memory corruption by sending a specially crafted authentication response during the login process. This affects the reliability of storage services and could lead to a denial-of-service condition.
Technical details
A heap-based buffer overflow exists in 'drivers/target/iscsi/iscsi_target_auth.c' within the 'chap_server_compute_hash()' function. The vulnerability occurs because the code fails to validate the length of a Base64-encoded 'CHAP_R' response before passing it to 'chap_base64_decode()'. While the destination buffer 'client_digest' is sized based on the expected hash (e.g., 32 bytes for SHA-256), the decoder can process up to 127 characters, resulting in up to 95 bytes of output and overflowing the buffer by up to 79 bytes. This can be triggered by a remote initiator during iSCSI login. Patches have been released for various stable kernel branches to validate the input length before decoding.
Affected products
- Linux Linux Kernel 1e5733883421 to 82454e6f21e56ea9a0a9de7d0ff7e1dfb83e34d6
Timeline
- 2026-05-21: other: Patch submitted by developer
- 2026-06-09: patched: Patch committed to stable tree
- 2026-07-19: disclosed: CVE published
References
- https://git.kernel.org/stable/c/4a3a19c98a8207ad08bec554703d90f2c34a8cc6
- https://git.kernel.org/stable/c/82454e6f21e56ea9a0a9de7d0ff7e1dfb83e34d6
- https://git.kernel.org/stable/c/85db7391310b1304d2dc8ae3b0b12105a9567147
- https://git.kernel.org/stable/c/bf154c657828ed05399bca5d98cf1611bb048b12
- https://git.kernel.org/stable/c/c04e85799356120209b351a148ac2db888d5ffd9
- https://git.kernel.org/stable/c/edd06675a02376ea8347dba7c29ad982ba5b36ee