Executive brief
A vulnerability in the Linux kernel's iSCSI target implementation could allow a remote attacker to crash the system. The issue occurs when the system handles specific iSCSI text commands, leading to memory errors. This can result in a 'kernel panic' or service outage, disrupting storage operations and network connectivity.
Technical details
The vulnerability consists of two flaws in 'iscsit_handle_text_cmd()'. First, a buffer overread occurs when 'iscsit_crc_buf()' uses an incorrect length ('rx_size' instead of the aligned payload length), reading 4 bytes past the allocated 'text_in' buffer during DataDigest CRC calculation. Second, a double-free occurs when a DataDigest mismatch happens with ErrorRecoveryLevel > 0; the 'text_in' buffer is freed but the pointer 'cmd->text_in_ptr' is not cleared, leading to a subsequent free during the next request or session teardown. An attacker can trigger these by sending malformed iSCSI Text PDUs. On systems with 'CONFIG_SLAB_FREELIST_HARDENED' enabled, this results in an immediate kernel BUG() and system halt.
Affected products
- Linux Linux Kernel v4.1 and later
Timeline
- 2026-04-18: other: Patch authored
- 2026-06-09: patched: Patch committed to stable tree
- 2026-07-19: advisory: CVE published
References
- https://git.kernel.org/stable/c/5118ea225fe63b44207ba88047e4866e1ea43812
- https://git.kernel.org/stable/c/6e22a1cdcc8277af4acc43710577157b77a02c5d
- https://git.kernel.org/stable/c/778c2ab142c625a8a8afa570e0f9b7873f445d99
- https://git.kernel.org/stable/c/89c81d1228c00fa6dd91de6c1c5aa1ef8a7875e3
- https://git.kernel.org/stable/c/badf178b76b0690851df00f4ca9cf2eb8eb0f963
- https://git.kernel.org/stable/c/d3e9b79aa794f7a23e82de4d710e7d2df610e349
- https://git.kernel.org/stable/c/ec9f19d52074a191ed1756ed4a7d39fff1a2085c