9.1
CVE-2026-90414
- EPSS 0.52%
- Veröffentlicht 17.09.2026 16:09:40
- Zuletzt bearbeitet 18.09.2026 18:17:58
- Erkennungen
IB/isert: reject PDUs declaring more data than was received
In the Linux kernel, the following vulnerability has been resolved:
IB/isert: reject PDUs declaring more data than was received
isert_recv_done() hands each received PDU to the opcode handlers without
ever looking at wc->byte_len, the number of bytes the HCA actually placed
in the receive descriptor. The handlers then copy that many bytes - the
data-segment length the initiator declared in the BHS
(ntoh24(hdr->dlength), via the derived unsol_data_len / imm_data_len) -
out of the fixed-size descriptor:
isert_handle_iscsi_dataout():
sg_copy_from_buffer(sg_start, sg_nents, isert_get_data(rx_desc),
unsol_data_len);
isert_handle_scsi_cmd():
sg_copy_from_buffer(cmd->se_cmd.t_data_sg, sg_nents,
isert_get_data(rx_desc), imm_data_len);
Because the declared length is never checked against wc->byte_len, an
initiator can declare a data segment larger than the bytes it actually
sent (and larger than the descriptor) and cause an out-of-bounds read of
the receive buffer.
Nothing upstream of isert closes this door:
- __iscsit_check_dataout_hdr() bounds the inbound payload against
conn_ops->MaxXmitDataSegmentLength (MXDSL) - a transmit parameter,
used here for the inbound check.
- iscsi_set_connection_parameters() sets
ops->MaxXmitDataSegmentLength = ops->TargetRecvDataSegmentLength;
and TARGETRECVDATASEGMENTLENGTH is absent from the min()-clamp list in
iscsi_check_acceptor_state(), so the value the initiator declares is
adopted verbatim (type range 512..16777215). The initiator effectively
raises its own ceiling.
- isert never clamps the negotiated value to its own fixed receive
descriptor (ISER_RX_SIZE, 9216 bytes), so the target core's bound and
the descriptor size are unrelated.
The imm_data_len == data_len path is more than an over-read: it aliases
the receive descriptor via sg_set_buf() and passes it to the backend as
the data source for the SCSI WRITE, so an over-declared length causes heap
contents past the descriptor to be written through the backend to the
backing store. The backend is the victim of the oversized scatterlist
isert hands it, not the cause; no read-back of the written bytes was
demonstrated.
Trigger: after login completes (full feature phase), an initiator that has
declared a large TargetRecvDataSegmentLength and a FirstBurstLength that
permits unsolicited/immediate data sends a PDU whose declared data-segment
length exceeds what was received. With KASAN:
BUG: KASAN: slab-out-of-bounds in sg_copy_buffer+0x150/0x1c0
Read of size 4096 at addr ffff888109720800 by task kworker/1:0H/25
Workqueue: ib-comp-wq ib_cq_poll_work
Call Trace:
sg_copy_buffer+0x150/0x1c0
isert_recv_done+0xba6/0x2390
__ib_process_cq+0xe1/0x390
ib_cq_poll_work+0x46/0x150
isert_recv_done+0xba6 resolves to isert_handle_iscsi_dataout()
(ib_isert.c:1160), inlined through isert_rx_opcode().
Validate wc->byte_len against the framing in isert_recv_done() before the
PDU reaches any handler, and reinstate the connection if it is short.
Because the test compares without subtracting the header length, it also
rejects PDUs shorter than the iSER and iSCSI headers, which would otherwise
be parsed out of stale descriptor contents. The login handler rejects PDUs
shorter than ISER_HEADERS_LEN (commit 29e7b925ae6d ("IB/isert: Reject login
PDUs shorter than ISER_HEADERS_LEN")) but does not bound the declared
length either; that is fixed in the next patch. The data handlers had no
length check at all.
isert reads the data segment from a fixed offset: isert_get_data()
returns the iSER header plus ISER_HEADERS_LEN and makes no adjustment for
an AHS. The bytes the handlers touch are therefore exactly
[ISER_HEADERS_LEN, ISER_HEADERS_LEN + dlength), and comparing that sum
against wc->byte_len bounds precisely the region that is read. An AHS
term would only make the test stricter without bounding anything furth
---truncated---Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
b8d26b3be8b33682cf163274ed07479a70554633
Version <
b4706722ed3ea72882b3c986a19b4a1ba66384c4
Status
affected
Version
b8d26b3be8b33682cf163274ed07479a70554633
Version <
bc58e9d3dc560220c57b8bdfc12af0cff1c8a43d
Status
affected
Version
b8d26b3be8b33682cf163274ed07479a70554633
Version <
274b1ad7e78338710864c4b4235bb1ce7e7107f9
Status
affected
Version
b8d26b3be8b33682cf163274ed07479a70554633
Version <
2a6b8f88fb7ee51714a1922a039225bdcaf12855
Status
affected
Version
b8d26b3be8b33682cf163274ed07479a70554633
Version <
39da0b7e1f530347d284cebcfc5b5afa90a173bf
Status
affected
Version
b8d26b3be8b33682cf163274ed07479a70554633
Version <
cf36fa5357a2fb25776a568d13a3653da7d99bcb
Status
affected
Version
b8d26b3be8b33682cf163274ed07479a70554633
Version <
352dc85324b29f5c85876f2666f3158b645e3f18
Status
affected
Version
b8d26b3be8b33682cf163274ed07479a70554633
Version <
957f92ea4022fb6af4618271615a2a21a7b5bef9
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
3.10
Status
affected
Version
0
Version <
3.10
Status
unaffected
Version <=
5.10.*
Version
5.10.270
Status
unaffected
Version <=
5.15.*
Version
5.15.221
Status
unaffected
Version <=
6.1.*
Version
6.1.188
Status
unaffected
Version <=
6.6.*
Version
6.6.157
Status
unaffected
Version <=
6.12.*
Version
6.12.110
Status
unaffected
Version <=
6.18.*
Version
6.18.52
Status
unaffected
Version <=
7.2.*
Version
7.2.6
Status
unaffected
Version <=
*
Version
7.3-rc1
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.52% | 0.432 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | 9.1 | 3.9 | 5.2 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
|
https://git.kernel.org/stable/c/b4706722ed3ea72882b3c986a19b4a1ba66384c4
https://git.kernel.org/stable/c/bc58e9d3dc560220c57b8bdfc12af0cff1c8a43d
https://git.kernel.org/stable/c/274b1ad7e78338710864c4b4235bb1ce7e7107f9
https://git.kernel.org/stable/c/2a6b8f88fb7ee51714a1922a039225bdcaf12855
https://git.kernel.org/stable/c/39da0b7e1f530347d284cebcfc5b5afa90a173bf
https://git.kernel.org/stable/c/cf36fa5357a2fb25776a568d13a3653da7d99bcb
https://git.kernel.org/stable/c/352dc85324b29f5c85876f2666f3158b645e3f18
https://git.kernel.org/stable/c/957f92ea4022fb6af4618271615a2a21a7b5bef9