SB20260816440 - Out-of-bounds read in Linux kernel target driver
Published: August 16, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Out-of-bounds read (CVE-ID: CVE-2026-72084)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in iSCSI PR-OUT TransportID parsing in the Linux kernel SCSI target subsystem when processing a crafted PERSISTENT RESERVE OUT TransportID buffer. A remote attacker can send a specially crafted PR OUT request to cause a denial of service.
The issue is reachable through any fabric that delivers a PR OUT to a device exported through an iSCSI target portal group, including a guest via vhost-scsi.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/004ccd2d3b4ac36a300e05e01df152e5c02a5a82
- https://git.kernel.org/stable/c/03fbc7de8d5e85fc8420e57e8304c855efd453ab
- https://git.kernel.org/stable/c/555a89846ed888d7401b3f7200934c0fbedcbb46
- https://git.kernel.org/stable/c/6ca5de8782e67573a61a6736b6dc0ffe58dcdf59
- https://git.kernel.org/stable/c/842248047ef28dbf3b3f7f49a0ec315054d4dab8
- https://git.kernel.org/stable/c/9298078a8f7d8181a04614a34ab655ccdf038204
- https://git.kernel.org/stable/c/d04a179085c262c9ed577d0a4cbc6482ff1fd9a3