Out-of-bounds read in Linux kernel - CVE-2026-90413
Published: September 18, 2026
Vulnerability details
The vulnerability allows a remote attacker to read out-of-bounds memory.
The vulnerability exists due to an out-of-bounds read in the iSER login PDU handling code when processing a login PDU whose declared data segment length exceeds the received payload length. A remote attacker can send a crafted login PDU with an oversized declared data segment length to read out-of-bounds memory.
The issue can be triggered before authentication.
Affected software
How to mitigate CVE-2026-90413
External References
- https://git.kernel.org/stable/c/0d9c0586af703890afe1bd0cfe641e3a3af1c32d
- https://git.kernel.org/stable/c/228aaa620fe6a7bc8b5b21dd348b4836b1760c61
- https://git.kernel.org/stable/c/2488b5b4827e5415768afc8daf097e8eb83c98df
- https://git.kernel.org/stable/c/44fe800ec13386c88bd5b32bcd1deaa1e17535d5
- https://git.kernel.org/stable/c/48812c8103071d550d9ab4a3431be5bdc52255bc
- https://git.kernel.org/stable/c/71ec8bbfa4a183f1e623662f9cfbcd702e433bdb
- https://git.kernel.org/stable/c/b1f3313e7b3e396e4985fea5c709477387e0a065
- https://git.kernel.org/stable/c/c345d9d0b3eefc990bb90cf565325785aab06aab