Race condition in Linux kernel - CVE-2026-90293
Published: September 18, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a race condition in the iSER target login receive-buffer handling when processing a SCSI command before the final Login Response. A remote attacker can send a SCSI command before receiving the final Login Response to cause a denial of service.
Affected software
How to mitigate CVE-2026-90293
External References
- https://git.kernel.org/stable/c/068fe9841d2585b79d479fc7b58251d02d0b066f
- https://git.kernel.org/stable/c/5247dde9daac7e107853b6fea043f7f47be033f7
- https://git.kernel.org/stable/c/6c506fee5a5f2c8719c65bcfc5e5d0862b0a1946
- https://git.kernel.org/stable/c/962edb9a6b0dae09d33a677485a398fc7d55968c
- https://git.kernel.org/stable/c/9b2c61344992c8c2b883e1eebe416cc488a19390
- https://git.kernel.org/stable/c/9c21a433022219ca899d1b3cd9049991f51a6a2c
- https://git.kernel.org/stable/c/ad4492dcaf90a1d1a728ec5eef1a68ce5355027a
- https://git.kernel.org/stable/c/d4f8257c3283919ca7e149381d062b9af5f7df7d