Junglewise Threat Intelligence

CVE-2026-63888: Linux Kernel iSCSI target double-free in iscsit_handle_text_cmd

CVE-2026-63888 · Severity: info · CVSS 7.5 · Published 2026-07-19

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's iSCSI target implementation could allow a remote attacker to crash the system. The issue occurs when the system handles specific iSCSI text commands, leading to memory errors. This can result in a 'kernel panic' or service outage, disrupting storage operations and network connectivity.

Technical details

The vulnerability consists of two flaws in 'iscsit_handle_text_cmd()'. First, a buffer overread occurs when 'iscsit_crc_buf()' uses an incorrect length ('rx_size' instead of the aligned payload length), reading 4 bytes past the allocated 'text_in' buffer during DataDigest CRC calculation. Second, a double-free occurs when a DataDigest mismatch happens with ErrorRecoveryLevel > 0; the 'text_in' buffer is freed but the pointer 'cmd->text_in_ptr' is not cleared, leading to a subsequent free during the next request or session teardown. An attacker can trigger these by sending malformed iSCSI Text PDUs. On systems with 'CONFIG_SLAB_FREELIST_HARDENED' enabled, this results in an immediate kernel BUG() and system halt.

Affected products

  • Linux Linux Kernel v4.1 and later

Timeline

  • 2026-04-18: other: Patch authored
  • 2026-06-09: patched: Patch committed to stable tree
  • 2026-07-19: advisory: CVE published

References

Related threats