Out-of-bounds read in Linux kernel - CVE-2026-90414
Published: September 18, 2026
Vulnerability details
The vulnerability allows a remote user to cause an out-of-bounds read and write heap contents beyond the receive descriptor to backing storage.
The vulnerability exists due to missing validation of the declared data segment length in isert_recv_done() when processing iSER/iSCSI PDUs. A remote user can send a PDU that declares a data segment larger than the received data to cause an out-of-bounds read and write heap contents beyond the receive descriptor to backing storage.
Exploitation requires the full feature phase and negotiated parameters that permit unsolicited or immediate data.
Affected software
How to mitigate CVE-2026-90414
External References
- https://git.kernel.org/stable/c/274b1ad7e78338710864c4b4235bb1ce7e7107f9
- https://git.kernel.org/stable/c/2a6b8f88fb7ee51714a1922a039225bdcaf12855
- https://git.kernel.org/stable/c/352dc85324b29f5c85876f2666f3158b645e3f18
- https://git.kernel.org/stable/c/39da0b7e1f530347d284cebcfc5b5afa90a173bf
- https://git.kernel.org/stable/c/957f92ea4022fb6af4618271615a2a21a7b5bef9
- https://git.kernel.org/stable/c/b4706722ed3ea72882b3c986a19b4a1ba66384c4
- https://git.kernel.org/stable/c/bc58e9d3dc560220c57b8bdfc12af0cff1c8a43d
- https://git.kernel.org/stable/c/cf36fa5357a2fb25776a568d13a3653da7d99bcb