SB20260918264 - Out-of-bounds read in Linux kernel ulp isert driver
Published: September 18, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Out-of-bounds read (CVE-ID: CVE-2026-90414)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to cause an out-of-bounds read and write heap contents beyond the receive descriptor to backing storage.
The vulnerability exists due to missing validation of the declared data segment length in isert_recv_done() when processing iSER/iSCSI PDUs. A remote user can send a PDU that declares a data segment larger than the received data to cause an out-of-bounds read and write heap contents beyond the receive descriptor to backing storage.
Exploitation requires the full feature phase and negotiated parameters that permit unsolicited or immediate data.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/274b1ad7e78338710864c4b4235bb1ce7e7107f9
- https://git.kernel.org/stable/c/2a6b8f88fb7ee51714a1922a039225bdcaf12855
- https://git.kernel.org/stable/c/352dc85324b29f5c85876f2666f3158b645e3f18
- https://git.kernel.org/stable/c/39da0b7e1f530347d284cebcfc5b5afa90a173bf
- https://git.kernel.org/stable/c/957f92ea4022fb6af4618271615a2a21a7b5bef9
- https://git.kernel.org/stable/c/b4706722ed3ea72882b3c986a19b4a1ba66384c4
- https://git.kernel.org/stable/c/bc58e9d3dc560220c57b8bdfc12af0cff1c8a43d
- https://git.kernel.org/stable/c/cf36fa5357a2fb25776a568d13a3653da7d99bcb