9.8

CVE-2026-72083

scsi: target: core: Fix iSCSI ISID use-after-free in REGISTER AND MOVE

In the Linux kernel, the following vulnerability has been resolved:

scsi: target: core: Fix iSCSI ISID use-after-free in REGISTER AND MOVE

core_scsi3_emulate_pro_register_and_move() maps the PERSISTENT RESERVE OUT
parameter list with transport_kmap_data_sg() and parses the destination
TransportID with target_parse_pr_out_transport_id(). For an iSCSI
TransportID (FORMAT CODE 01b), iscsi_parse_pr_out_transport_id() returns
the ISID in iport_ptr as a raw pointer into that mapped buffer.

The function then unmaps the buffer with transport_kunmap_data_sg() before
dereferencing iport_ptr in strcmp(), __core_scsi3_locate_pr_reg() and
core_scsi3_alloc_registration(). When the parameter list spans more than
one page (PARAMETER LIST LENGTH > 4096), transport_kmap_data_sg() uses
vmap() and transport_kunmap_data_sg() does vunmap(), so the kernel virtual
address backing iport_ptr is torn down and every subsequent dereference is
a use-after-free read of the unmapped region.

Keep the parameter list mapped until iport_ptr is no longer needed: drop
the early transport_kunmap_data_sg() and unmap once on the success path,
right before returning. The error paths already unmap through the existing
"if (buf) transport_kunmap_data_sg(cmd)" at the out: label, which now runs
on every post-map error exit because buf is no longer cleared early. Only
reads of the mapping happen while spinlocks are held; the map and unmap
calls remain outside any lock. The sibling caller
core_scsi3_decode_spec_i_port() already uses the buffer before unmapping it
and is left unchanged.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 4949314c7283ea4f9ade182ca599583b89f7edd6
Version < 7d56f5c868d92c9d504a34a3ea450bce481c7f63
Status affected
Version 4949314c7283ea4f9ade182ca599583b89f7edd6
Version < 59a2a5a37dc49a641ad6bc64aee34e5a61025ffd
Status affected
Version 4949314c7283ea4f9ade182ca599583b89f7edd6
Version < 9f8076cc73dfa6b10155978c160587e986b22169
Status affected
Version 4949314c7283ea4f9ade182ca599583b89f7edd6
Version < a040004846f1fbe687f6ec76d9ccc27b4ead42e4
Status affected
Version 4949314c7283ea4f9ade182ca599583b89f7edd6
Version < 05b3e37433cf2eaf8867f1c16528aa347bb212ab
Status affected
Version 4949314c7283ea4f9ade182ca599583b89f7edd6
Version < cb7bdae7fba404852ade34b0c1445fbaf3e54fbb
Status affected
Version 4949314c7283ea4f9ade182ca599583b89f7edd6
Version < ef2ee18fec92088c7d8877baf7674e89389ccd66
Status affected
Version 4949314c7283ea4f9ade182ca599583b89f7edd6
Version < fda6a1f3c3d7047b5ce5654487649c2daa738bfc
Status affected
Version d2227f84ba0e97906153ac83db13213fb2e3938d
Status affected
Version 3.2.9
Version < 3.3
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 3.3
Status affected
Version 0
Version < 3.3
Status unaffected
Version <= 5.10.*
Version 5.10.261
Status unaffected
Version <= 5.15.*
Version 5.15.212
Status unaffected
Version <= 6.1.*
Version 6.1.178
Status unaffected
Version <= 6.6.*
Version 6.6.145
Status unaffected
Version <= 6.12.*
Version 6.12.97
Status unaffected
Version <= 6.18.*
Version 6.18.40
Status unaffected
Version <= 7.1.*
Version 7.1.5
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.73% 0.514
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/7d56f5c868d92c9d504a34a3ea450bce481c7f63
https://git.kernel.org/stable/c/59a2a5a37dc49a641ad6bc64aee34e5a61025ffd
https://git.kernel.org/stable/c/9f8076cc73dfa6b10155978c160587e986b22169
https://git.kernel.org/stable/c/a040004846f1fbe687f6ec76d9ccc27b4ead42e4
https://git.kernel.org/stable/c/05b3e37433cf2eaf8867f1c16528aa347bb212ab
https://git.kernel.org/stable/c/cb7bdae7fba404852ade34b0c1445fbaf3e54fbb
https://git.kernel.org/stable/c/ef2ee18fec92088c7d8877baf7674e89389ccd66
https://git.kernel.org/stable/c/fda6a1f3c3d7047b5ce5654487649c2daa738bfc