SB20260918377 - Race condition in Linux kernel ulp isert driver
Published: September 18, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Race condition (CVE-ID: CVE-2026-90293)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a race condition in the iSER target login receive-buffer handling when processing a SCSI command before the final Login Response. A remote attacker can send a SCSI command before receiving the final Login Response to cause a denial of service.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/068fe9841d2585b79d479fc7b58251d02d0b066f
- https://git.kernel.org/stable/c/5247dde9daac7e107853b6fea043f7f47be033f7
- https://git.kernel.org/stable/c/6c506fee5a5f2c8719c65bcfc5e5d0862b0a1946
- https://git.kernel.org/stable/c/962edb9a6b0dae09d33a677485a398fc7d55968c
- https://git.kernel.org/stable/c/9b2c61344992c8c2b883e1eebe416cc488a19390
- https://git.kernel.org/stable/c/9c21a433022219ca899d1b3cd9049991f51a6a2c
- https://git.kernel.org/stable/c/ad4492dcaf90a1d1a728ec5eef1a68ce5355027a
- https://git.kernel.org/stable/c/d4f8257c3283919ca7e149381d062b9af5f7df7d