Junglewise Threat Intelligence

CVE-2026-90294: Linux kernel IB/isert NULL pointer dereference in session registration

CVE-2026-90294 · Severity: high · CVSS 7.5 · Published 2026-09-17

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's InfiniBand iSER transport layer has a race condition where a SCSI command can be executed before the iSCSI session is fully registered. This causes a NULL pointer dereference in the kernel, leading to a crash that disrupts storage operations and availability for systems using InfiniBand-based iSCSI targets.

Technical details

The vulnerability is a NULL pointer dereference (CWE-476) in the IB/isert (InfiniBand iSER) driver. The root cause is a race condition where isert_put_login_tx() sends the final iSCSI Login Response before __transport_register_session() completes, allowing an initiator to send SCSI commands against a se_session with a NULL se_tpg pointer. The attack vector is network-based and requires no special privileges, but depends on precise timing: an initiator that immediately issues a command after receiving the Login Response will trigger the NULL dereference in target_submit() running in the ib-comp-wq worker thread. The fix delays the final Login Response until after session registration is complete, preventing the race condition.

Affected products

  • Linux Linux kernel 7.2.0-rc5 and prior versions

Timeline

  • 2026-09-17: disclosed
  • 2026-09-17: patched: Fix resolves the race condition by delaying Login Response until session registration

Related threats