9.8

CVE-2026-63887

scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf

In the Linux kernel, the following vulnerability has been resolved:

scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf

iscsi_encode_text_output() concatenates "key=value\0" records into
login->rsp_buf, an 8192-byte kzalloc(MAX_KEY_VALUE_PAIRS) buffer
allocated in iscsit_alloc_login_setup_buffer(). The three sprintf() call
sites in this function (lines 1398, 1411, 1424 in v7.1-rc2) never check
the remaining buffer capacity:

	*length += sprintf(output_buf, "%s=%s", er->key, er->value);
	*length += 1;
	output_buf = textbuf + *length;

The 8192-byte ceiling at iscsi_target_check_login_request() bounds the
*input* Login PDU payload, but a single PDU can carry up to 2048 minimal
four-byte "a=b\0" pairs, each unknown key expanding to a 16-byte
"a=NotUnderstood\0" output record via iscsi_add_notunderstood_response().
2048 * 16 = 32 KiB of output into an 8 KiB buffer, producing a ~24 KiB
heap overrun in the kmalloc-8k slab.

The fix introduces a static iscsi_encode_text_record() helper that uses
snprintf() with a per-call bounds check against the remaining buffer,
and threads a u32 textbuf_size parameter through
iscsi_encode_text_output(). Both call sites in
iscsi_target_handle_csg_zero() (PHASE_SECURITY) and
iscsi_target_handle_csg_one() (PHASE_OPERATIONAL) pass
MAX_KEY_VALUE_PAIRS. On overflow the encoder logs the condition, calls
iscsi_release_extra_responses() to drop queued records, and returns -1;
both caller sites now emit ISCSI_STATUS_CLS_INITIATOR_ERR /
ISCSI_LOGIN_STATUS_INIT_ERR via iscsit_tx_login_rsp() before returning,
so the initiator sees an explicit failed-login response rather than a
silent connection drop. (Prior to this patch only the PHASE_OPERATIONAL
caller did that; the PHASE_SECURITY caller is converted to the same
shape.)
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version e48354ce078c079996f89d715dfa44814b4eba01
Version < cb84e974fb172bc71386289f37b78ea679410b39
Status affected
Version e48354ce078c079996f89d715dfa44814b4eba01
Version < b19382dfc6e7dee6d3859ba44b6ca29e97a51627
Status affected
Version e48354ce078c079996f89d715dfa44814b4eba01
Version < efe633e600a0ac68357206fede21b1ac8178f3b8
Status affected
Version e48354ce078c079996f89d715dfa44814b4eba01
Version < 4e9f0c4a645c995bc75c06c7b3644254ffb4c76b
Status affected
Version e48354ce078c079996f89d715dfa44814b4eba01
Version < 30bf335e8fe170322080ee001f05ca29c50680b3
Status affected
Version e48354ce078c079996f89d715dfa44814b4eba01
Version < 594a40360012ce5f94c715d5e3b20fa3af7d525a
Status affected
Version e48354ce078c079996f89d715dfa44814b4eba01
Version < 26e4a304b7e6f1338c675d527608d32549c091db
Status affected
Version e48354ce078c079996f89d715dfa44814b4eba01
Version < bf33e01f88388c43e285492a63e539df6ffed64c
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 3.1
Status affected
Version 0
Version < 3.1
Status unaffected
Version <= 5.10.*
Version 5.10.259
Status unaffected
Version <= 5.15.*
Version 5.15.210
Status unaffected
Version <= 6.1.*
Version 6.1.176
Status unaffected
Version <= 6.6.*
Version 6.6.143
Status unaffected
Version <= 6.12.*
Version 6.12.93
Status unaffected
Version <= 6.18.*
Version 6.18.35
Status unaffected
Version <= 7.0.*
Version 7.0.12
Status unaffected
Version <= *
Version 7.1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.75% 0.51
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/cb84e974fb172bc71386289f37b78ea679410b39
https://git.kernel.org/stable/c/b19382dfc6e7dee6d3859ba44b6ca29e97a51627
https://git.kernel.org/stable/c/efe633e600a0ac68357206fede21b1ac8178f3b8
https://git.kernel.org/stable/c/4e9f0c4a645c995bc75c06c7b3644254ffb4c76b
https://git.kernel.org/stable/c/30bf335e8fe170322080ee001f05ca29c50680b3
https://git.kernel.org/stable/c/594a40360012ce5f94c715d5e3b20fa3af7d525a
https://git.kernel.org/stable/c/26e4a304b7e6f1338c675d527608d32549c091db
https://git.kernel.org/stable/c/bf33e01f88388c43e285492a63e539df6ffed64c