Executive brief
The Linux kernel's InfiniBand iSER transport layer has a race condition where a SCSI command can be executed before the iSCSI session is fully registered. This causes a NULL pointer dereference in the kernel, leading to a crash that disrupts storage operations and availability for systems using InfiniBand-based iSCSI targets.
Technical details
The vulnerability is a NULL pointer dereference (CWE-476) in the IB/isert (InfiniBand iSER) driver. The root cause is a race condition where isert_put_login_tx() sends the final iSCSI Login Response before __transport_register_session() completes, allowing an initiator to send SCSI commands against a se_session with a NULL se_tpg pointer. The attack vector is network-based and requires no special privileges, but depends on precise timing: an initiator that immediately issues a command after receiving the Login Response will trigger the NULL dereference in target_submit() running in the ib-comp-wq worker thread. The fix delays the final Login Response until after session registration is complete, preventing the race condition.
Affected products
- Linux Linux kernel 7.2.0-rc5 and prior versions
Timeline
- 2026-09-17: disclosed
- 2026-09-17: patched: Fix resolves the race condition by delaying Login Response until session registration