SB20260816446 - Use-after-free in Linux kernel target driver
Published: August 16, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Use-after-free (CVE-ID: CVE-2026-72083)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to a use-after-free in core_scsi3_emulate_pro_register_and_move() when processing a crafted iSCSI TransportID in a PERSISTENT RESERVE OUT REGISTER AND MOVE parameter list. A remote user can send a specially crafted request to cause a denial of service.
The issue is triggered when the parameter list spans more than one page, causing the ISID pointer to reference an unmapped region after the buffer is torn down.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/05b3e37433cf2eaf8867f1c16528aa347bb212ab
- https://git.kernel.org/stable/c/59a2a5a37dc49a641ad6bc64aee34e5a61025ffd
- https://git.kernel.org/stable/c/7d56f5c868d92c9d504a34a3ea450bce481c7f63
- https://git.kernel.org/stable/c/9f8076cc73dfa6b10155978c160587e986b22169
- https://git.kernel.org/stable/c/a040004846f1fbe687f6ec76d9ccc27b4ead42e4
- https://git.kernel.org/stable/c/cb7bdae7fba404852ade34b0c1445fbaf3e54fbb
- https://git.kernel.org/stable/c/ef2ee18fec92088c7d8877baf7674e89389ccd66
- https://git.kernel.org/stable/c/fda6a1f3c3d7047b5ce5654487649c2daa738bfc