{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-90413","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.813Z","datePublished":"2026-09-17T16:09:39.383Z","dateUpdated":"2026-09-18T17:55:14.522Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-18T17:55:14.522Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nIB/isert: reject login PDUs declaring more data than was received\n\nisert_login_recv_done() records how many bytes the HCA actually placed in\nthe login buffer, but nothing compares that against the length the login\nPDU's BHS declares.  isert_rx_login_req() copies min(login_req_len,\nMAX_KEY_VALUE_PAIRS) bytes into login->req_buf, and the login code then\nreads the declared length back out of that buffer - for the first PDU in\niscsi_target_locate_portal(),\n\n\tpayload_length = ntoh24(login_req->dlength);\n\ttmpbuf = kmemdup_nul(login->req_buf, payload_length, GFP_KERNEL);\n\nand for the ones after it in iscsi_decode_text_input(), reached from\niscsi_target_do_login().\n\nlogin->req_buf is a fixed MAX_KEY_VALUE_PAIRS (8192) byte allocation, so\nan initiator that declares more than it sends reads off the end of it,\nbefore authentication and with the length under its control:\n\n  BUG: KASAN: slab-out-of-bounds in kmemdup_nul+0x43/0x80\n  Read of size 8193 at addr ffff8881056a8000 by task iscsi_np/167\n   __asan_memcpy+0x23/0x60\n   kmemdup_nul+0x43/0x80\n   iscsi_target_locate_portal+0x48d/0x1180\n   iscsi_target_login_thread+0x19a9/0x3350\n  Allocated by task 167:\n   __kmalloc_cache_noprof+0x158/0x370\n   iscsi_target_login_thread+0x971/0x3350\n  which belongs to the cache kmalloc-8k of size 8192\n  allocated 8192-byte region\n\nFalsifying the second login PDU instead reaches the other reader, on the\nsame buffer:\n\n  BUG: KASAN: slab-out-of-bounds in kmemdup_nul+0x43/0x80\n  Read of size 8193 at addr ffff888104d10000 by task kworker/1:1/50\n  Workqueue: isert_login_wq iscsi_target_do_login_rx\n   __asan_memcpy+0x23/0x60\n   kmemdup_nul+0x43/0x80\n   iscsi_decode_text_input+0xc6/0x11c0\n   iscsi_target_do_login+0x261/0x1470\n   iscsi_target_do_login_rx+0x51d/0x7d0\n\niscsit over TCP is not exposed: iscsit_get_login_rx() validates the\ndeclared length with iscsi_target_check_login_request() and then reads\nexactly that many bytes off the socket, so the declared length governs\nhow much arrives rather than how much is copied out of an already-filled\nbuffer.  isert does not call iscsi_target_check_login_request() at all.\n\nReject a login PDU whose declared DataSegmentLength exceeds what was\nreceived, in both paths that reach isert_rx_login_req():\nisert_get_login_rx() for the first login PDU and isert_login_recv_done()\nfor the ones after it.  dlength <= login_req_len is allowed because the\nreceived count can include up to three bytes of iSCSI padding.\n\nOnce the check is in place the copy out can no longer exceed the copy in:\nthe posted login SGE is ISER_RX_PAYLOAD_SIZE, so login_req_len cannot\nexceed MAX_KEY_VALUE_PAIRS and the min() in isert_rx_login_req() is\nlogin_req_len.\n\nLike the existing short-PDU check added by 29e7b925ae6d, the reject in\nisert_login_recv_done() returns without completing login_req_comp, so a\nmalformed subsequent PDU leaves the login to be torn down by the login\ntimer rather than failing immediately.  The first-PDU path returns an\nerror and fails straight away.\n\nReproduced on 7.2.0-rc4 with soft-RoCE (rdma_rxe) under KASAN, using an\ninitiator that sends the real key=value payload while declaring 8193 in\nthe BHS, on the first login PDU and on the second in separate runs.  The\nreported read size tracks the declared value exactly; 16384 and 61440\nbehave the same.  Unpatched 3 of 3 runs report on each of the two paths,\npatched 0 of 3 on both, run alternately in a single session, and a normal\nlogin still completes on the patched build."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","baseScore":9.1,"baseSeverity":"CRITICAL"},"scenarios":[{"lang":"en","value":"AV:N - The forged length is the iSCSI Login Request BHS DataSegmentLength (hdr->dlength) delivered in an RDMA Send that completes in isert_login_recv_done(); isert_setup_id() rdma_bind_addr()/rdma_listen()s that portal on an IP sockaddr with RDMA_PS_TCP (RoCEv2/iWARP), so the bytes arrive on a routable IP transport.\nAC:L - The initiator sets dlength independently of wc->byte_len. isert_rx_login_req() copies only min(login_req_len, MAX_KEY_VALUE_PAIRS) into login->req_buf, then iscsi_target_locate_portal()/iscsi_decode_text_input() pass ntoh24(dlength) to kmemdup_nul(); declared lengths 8193, 16384 and 61440 hit with no race.\nPR:N - iscsi_target_locate_portal() runs in iscsi_target_login_thread() immediately after isert_get_login_rx() returns the first Login Request, before iscsi_target_start_negotiation() or CHAP; isert_connect_request() accepts the RDMA CM CONNECT_REQUEST whenever np->enabled, with no credentials.\nUI:N - The attacker itself performs the RDMA CM connect and sends the crafted Login Request; no local user action is required once the isert portal is already listening.\nS:U - kmemdup_nul() over-reads the host kernel's login->req_buf in iscsi_target_locate_portal() and iscsi_decode_text_input() on the iSER target; the impact stays in that kernel and does not cross a guest/host or IOMMU boundary.\nC:H - ntoh24(login_req->dlength) is a 24-bit attacker-chosen size passed to kmemdup_nul(login->req_buf, payload_length), which memcpy-reads that many bytes from the 8192-byte req_buf object, an unbounded slab-out-of-bounds read of adjacent kernel memory rather than a few-byte leak.\nI:N - kmemdup_nul() writes only into a newly allocated tmpbuf of size payload_length+1, so the bug is a source over-read of req_buf, not a write into neighboring objects; parsing that copy as key=value does not give the initiator an attacker-controlled kernel write.\nA:H - KASAN reports a slab-out-of-bounds read in kmemdup_nul() from iscsi_target_locate_portal() on the first PDU and from iscsi_decode_text_input() on later PDUs; a declared length of 61440 walks tens of kilobytes past the kmalloc-8k object and faults the target."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/infiniband/ulp/isert/ib_isert.c"],"versions":[{"version":"b8d26b3be8b33682cf163274ed07479a70554633","lessThan":"b1f3313e7b3e396e4985fea5c709477387e0a065","status":"affected","versionType":"git"},{"version":"b8d26b3be8b33682cf163274ed07479a70554633","lessThan":"228aaa620fe6a7bc8b5b21dd348b4836b1760c61","status":"affected","versionType":"git"},{"version":"b8d26b3be8b33682cf163274ed07479a70554633","lessThan":"0d9c0586af703890afe1bd0cfe641e3a3af1c32d","status":"affected","versionType":"git"},{"version":"b8d26b3be8b33682cf163274ed07479a70554633","lessThan":"44fe800ec13386c88bd5b32bcd1deaa1e17535d5","status":"affected","versionType":"git"},{"version":"b8d26b3be8b33682cf163274ed07479a70554633","lessThan":"71ec8bbfa4a183f1e623662f9cfbcd702e433bdb","status":"affected","versionType":"git"},{"version":"b8d26b3be8b33682cf163274ed07479a70554633","lessThan":"c345d9d0b3eefc990bb90cf565325785aab06aab","status":"affected","versionType":"git"},{"version":"b8d26b3be8b33682cf163274ed07479a70554633","lessThan":"48812c8103071d550d9ab4a3431be5bdc52255bc","status":"affected","versionType":"git"},{"version":"b8d26b3be8b33682cf163274ed07479a70554633","lessThan":"2488b5b4827e5415768afc8daf097e8eb83c98df","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/infiniband/ulp/isert/ib_isert.c"],"versions":[{"version":"3.10","status":"affected"},{"version":"0","lessThan":"3.10","status":"unaffected","versionType":"semver"},{"version":"5.10.270","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.221","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.188","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.110","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.52","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.6","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.10","versionEndExcluding":"5.10.270"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.10","versionEndExcluding":"5.15.221"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.10","versionEndExcluding":"6.1.188"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.10","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.10","versionEndExcluding":"6.12.110"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.10","versionEndExcluding":"6.18.52"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.10","versionEndExcluding":"7.2.6"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.10","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/b1f3313e7b3e396e4985fea5c709477387e0a065"},{"url":"https://git.kernel.org/stable/c/228aaa620fe6a7bc8b5b21dd348b4836b1760c61"},{"url":"https://git.kernel.org/stable/c/0d9c0586af703890afe1bd0cfe641e3a3af1c32d"},{"url":"https://git.kernel.org/stable/c/44fe800ec13386c88bd5b32bcd1deaa1e17535d5"},{"url":"https://git.kernel.org/stable/c/71ec8bbfa4a183f1e623662f9cfbcd702e433bdb"},{"url":"https://git.kernel.org/stable/c/c345d9d0b3eefc990bb90cf565325785aab06aab"},{"url":"https://git.kernel.org/stable/c/48812c8103071d550d9ab4a3431be5bdc52255bc"},{"url":"https://git.kernel.org/stable/c/2488b5b4827e5415768afc8daf097e8eb83c98df"}],"title":"IB/isert: reject login PDUs declaring more data than was received","x_generator":{"engine":"bippy-1.2.0"}}}}