CVE-2026-63888
In the Linux kernel, the following vulnerability has been resolved:
scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd()
Two latent bugs in the Text-phase handler, both present since the original LIO integration in commit e48354ce078c ("iscsi-target: Add iSCSI fabric support for target v4.1"):
1) DataDigest CRC buffer overread (4 bytes past text_in).
Both fixes are one-liners. The Text PDU state machine is unchanged and the wire protocol is unaffected.
Detalles técnicos trazas, registros y código del informe original
text_in is kzalloc()'d at ALIGN(payload_length, 4). rx_size is then
incremented by ISCSI_CRC_LEN to make room for the received DataDigest
in the iovec, but the same (now-bumped) rx_size is passed as the
buffer length to iscsit_crc_buf():
if (conn->conn_ops->DataDigest) {
...
rx_size += ISCSI_CRC_LEN;
}
...
if (conn->conn_ops->DataDigest) {
data_crc = iscsit_crc_buf(text_in, rx_size, 0, NULL);
iscsit_crc_buf() walks rx_size bytes of text_in with crc32c(), so
when DataDigest is negotiated it reads 4 bytes past the end of the
text_in allocation. KASAN reproduces this directly on the unpatched
mainline tree as slab-out-of-bounds in crc32c() called from the Text
PDU path. The OOB bytes feed crc32c() and are then compared against
the initiator-supplied checksum, so the value does not flow back to
the attacker, but the kernel does read past the buffer on every Text
PDU with DataDigest=CRC32C.
Fix by passing the actual padded payload length
(ALIGN(payload_length, 4)) that was used for the kzalloc().
2) Stale cmd->text_in_ptr re-free (double-free) on ERL>0 bad DataDigest
drop.
On DataDigest mismatch with ErrorRecoveryLevel > 0 the handler
silently drops the PDU and lets the initiator plug the CmdSN gap:
kfree(text_in);
return 0;
cmd->text_in_ptr still points at the freed buffer. The next Text
Request on the same ITT re-enters iscsit_setup_text_cmd(), which
unconditionally does
kfree(cmd->text_in_ptr);
cmd->text_in_ptr = NULL;
freeing the same pointer a second time. Session teardown via
iscsit_release_cmd() has the same shape and hits the same double-free
if the connection is dropped before a second Text Request arrives.
On an unmodified mainline tree the bug-1 CRC overread fires first on
the initial valid Text Request and perturbs the subsequent state, so
#4 was isolated by building a kernel with only the bug-1 hunk of this
patch applied plus temporary printk() observability around the three
relevant kfree() sites. The observability prints are not part of
this patch. On that build, a three-PDU Text Request sequence after
login produces two back-to-back splats:
BUG: KASAN: double-free in iscsit_setup_text_cmd+0x??
BUG: KASAN: double-free in iscsit_release_cmd+0x??
showing the same pointer freed in the ERL>0 drop path and again in
iscsit_setup_text_cmd() (next Text Request on the same ITT) and once
more in iscsit_release_cmd() (session teardown). On distro kernels
with CONFIG_SLAB_FREELIST_HARDENED=y (default) the double-free
becomes a remote kernel BUG(); on non-hardened kernels it corrupts
the slab freelist.
Fix by clearing cmd->text_in_ptr after the kfree() in the ERL>0 drop
path. With both hunks applied #4 is directly observable on the stock
tree without observability printks; fixing bug-1 alone would mask #4
less, not more, so the hunks are submitted together.CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 9.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.78%
- Percentil entre todas las CVEs puntuadas: 54
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1190Exploit Public-Facing Applicationinitial access85 % - Impacto principal
T1499.004Application or System Exploitationimpact80 %
Vulnerabilidad en kernel Linux accesible remotamente sin autenticación (AV:N, PR:N). Buffer overread y double-free en iSCSI target permiten DoS y corrupción de memoria de slab freelist.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/5118ea225fe63b44207ba88047e4866e1ea43812
- https://git.kernel.org/stable/c/6e22a1cdcc8277af4acc43710577157b77a02c5d
- https://git.kernel.org/stable/c/778c2ab142c625a8a8afa570e0f9b7873f445d99
- https://git.kernel.org/stable/c/89c81d1228c00fa6dd91de6c1c5aa1ef8a7875e3
- https://git.kernel.org/stable/c/badf178b76b0690851df00f4ca9cf2eb8eb0f963
- https://git.kernel.org/stable/c/d3e9b79aa794f7a23e82de4d710e7d2df610e349
- https://git.kernel.org/stable/c/ec9f19d52074a191ed1756ed4a7d39fff1a2085c
- https://git.kernel.org/stable/c/f7948af0dd03de84079dcd4dc215a69fd6fbb95d
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-63888",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Secondary",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "e48354ce078c079996f89d715dfa44814b4eba01",
"lessThan": "f7948af0dd03de84079dcd4dc215a69fd6fbb95d",
"versionType": "git"
},
{
"status": "affected",
"version": "e48354ce078c079996f89d715dfa44814b4eba01",
"lessThan": "badf178b76b0690851df00f4ca9cf2eb8eb0f963",
"versionType": "git"
},
{
"status": "affected",
"version": "e48354ce078c079996f89d715dfa44814b4eba01",
"lessThan": "6e22a1cdcc8277af4acc43710577157b77a02c5d",
"versionType": "git"
},
{
"status": "affected",
"version": "e48354ce078c079996f89d715dfa44814b4eba01",
"lessThan": "d3e9b79aa794f7a23e82de4d710e7d2df610e349",
"versionType": "git"
},
{
"status": "affected",
"version": "e48354ce078c079996f89d715dfa44814b4eba01",
"lessThan": "ec9f19d52074a191ed1756ed4a7d39fff1a2085c",
"versionType": "git"
},
{
"status": "affected",
"version": "e48354ce078c079996f89d715dfa44814b4eba01",
"lessThan": "89c81d1228c00fa6dd91de6c1c5aa1ef8a7875e3",
"versionType": "git"
},
{
"status": "affected",
"version": "e48354ce078c079996f89d715dfa44814b4eba01",
"lessThan": "5118ea225fe63b44207ba88047e4866e1ea43812",
"versionType": "git"
},
{
"status": "affected",
"version": "e48354ce078c079996f89d715dfa44814b4eba01",
"lessThan": "778c2ab142c625a8a8afa570e0f9b7873f445d99",
"versionType": "git"
}
],
"programFiles": [
"drivers/target/iscsi/iscsi_target.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "3.1"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "3.1",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.10.259",
"versionType": "semver",
"lessThanOrEqual": "5.10.*"
},
{
"status": "unaffected",
"version": "5.15.210",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.176",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.143",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.93",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.35",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.0.12",
"versionType": "semver",
"lessThanOrEqual": "7.0.*"
},
{
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/target/iscsi/iscsi_target.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-07-19T16:17:05.997",
"references": [
{
"url": "https://git.kernel.org/stable/c/5118ea225fe63b44207ba88047e4866e1ea43812",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/6e22a1cdcc8277af4acc43710577157b77a02c5d",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/778c2ab142c625a8a8afa570e0f9b7873f445d99",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/89c81d1228c00fa6dd91de6c1c5aa1ef8a7875e3",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/badf178b76b0690851df00f4ca9cf2eb8eb0f963",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/d3e9b79aa794f7a23e82de4d710e7d2df610e349",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/ec9f19d52074a191ed1756ed4a7d39fff1a2085c",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/f7948af0dd03de84079dcd4dc215a69fd6fbb95d",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Awaiting Analysis",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd()\n\nTwo latent bugs in the Text-phase handler, both present since the\noriginal LIO integration in commit e48354ce078c (\"iscsi-target: Add\niSCSI fabric support for target v4.1\"):\n\n1) DataDigest CRC buffer overread (4 bytes past text_in).\n\n text_in is kzalloc()'d at ALIGN(payload_length, 4). rx_size is then\n incremented by ISCSI_CRC_LEN to make room for the received DataDigest\n in the iovec, but the same (now-bumped) rx_size is passed as the\n buffer length to iscsit_crc_buf():\n\n if (conn->conn_ops->DataDigest) {\n ...\n rx_size += ISCSI_CRC_LEN;\n }\n ...\n if (conn->conn_ops->DataDigest) {\n data_crc = iscsit_crc_buf(text_in, rx_size, 0, NULL);\n\n iscsit_crc_buf() walks rx_size bytes of text_in with crc32c(), so\n when DataDigest is negotiated it reads 4 bytes past the end of the\n text_in allocation. KASAN reproduces this directly on the unpatched\n mainline tree as slab-out-of-bounds in crc32c() called from the Text\n PDU path. The OOB bytes feed crc32c() and are then compared against\n the initiator-supplied checksum, so the value does not flow back to\n the attacker, but the kernel does read past the buffer on every Text\n PDU with DataDigest=CRC32C.\n\n Fix by passing the actual padded payload length\n (ALIGN(payload_length, 4)) that was used for the kzalloc().\n\n2) Stale cmd->text_in_ptr re-free (double-free) on ERL>0 bad DataDigest\n drop.\n\n On DataDigest mismatch with ErrorRecoveryLevel > 0 the handler\n silently drops the PDU and lets the initiator plug the CmdSN gap:\n\n kfree(text_in);\n return 0;\n\n cmd->text_in_ptr still points at the freed buffer. The next Text\n Request on the same ITT re-enters iscsit_setup_text_cmd(), which\n unconditionally does\n\n kfree(cmd->text_in_ptr);\n cmd->text_in_ptr = NULL;\n\n freeing the same pointer a second time. Session teardown via\n iscsit_release_cmd() has the same shape and hits the same double-free\n if the connection is dropped before a second Text Request arrives.\n\n On an unmodified mainline tree the bug-1 CRC overread fires first on\n the initial valid Text Request and perturbs the subsequent state, so\n #4 was isolated by building a kernel with only the bug-1 hunk of this\n patch applied plus temporary printk() observability around the three\n relevant kfree() sites. The observability prints are not part of\n this patch. On that build, a three-PDU Text Request sequence after\n login produces two back-to-back splats:\n\n BUG: KASAN: double-free in iscsit_setup_text_cmd+0x??\n BUG: KASAN: double-free in iscsit_release_cmd+0x??\n\n showing the same pointer freed in the ERL>0 drop path and again in\n iscsit_setup_text_cmd() (next Text Request on the same ITT) and once\n more in iscsit_release_cmd() (session teardown). On distro kernels\n with CONFIG_SLAB_FREELIST_HARDENED=y (default) the double-free\n becomes a remote kernel BUG(); on non-hardened kernels it corrupts\n the slab freelist.\n\n Fix by clearing cmd->text_in_ptr after the kfree() in the ERL>0 drop\n path. With both hunks applied #4 is directly observable on the stock\n tree without observability printks; fixing bug-1 alone would mask #4\n less, not more, so the hunks are submitted together.\n\nBoth fixes are one-liners. The Text PDU state machine is unchanged and\nthe wire protocol is unaffected."
}
],
"lastModified": "2026-07-27T17:44:23.777",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}