CVE-2026-98357
In the Linux kernel, the following vulnerability has been resolved:
IB/isert: wait for deferred control PDU completions before releasing the connection
isert_send_done() hands ISTATE_SEND_TASKMGTRSP, ISTATE_SEND_REJECT and ISTATE_SEND_TEXTRSP completions off to isert_comp_wq and returns. The work item then runs isert_completion_put() -> isert_put_cmd(), which reads isert_conn->conn and takes conn->cmd_lock.
Nothing orders that work item against teardown. isert_wait_conn() queues isert_release_work, which frees isert_conn, and iscsit_close_connection() frees the iscsit_conn right after it returns, so the queued work can run against freed memory.
Leer descripción completaMostrar menos
Count the deferred control PDU completions per connection and let isert_wait_conn() wait for them before the release work is queued.
ISTATE_SEND_LOGOUTRSP is deliberately not counted: that branch runs iscsit_logout_post_handler(), which ends up waiting for conn->conn_wait_comp, and that completion is only sent by iscsit_close_connection() after it has called iscsit_wait_conn(). Waiting for it here would deadlock. Its wait stays the existing isert_wait4logout().
The splat below is from a kernel with tracing printk()s and an msleep(200) injected into isert_do_control_comp() to widen the window:
Detalles técnicos trazas, registros y código del informe original
BUG: KASAN: slab-use-after-free in isert_put_cmd+0x53d/0x620 Read of size 8 at addr ffff8881054f1038 by task kworker/u17:1/182 CPU: 0 UID: 0 PID: 182 Comm: kworker/u17:1 Tainted: G B 7.2.0-rc5-TWIDE-gb8babf08acc7 #1 PREEMPT(lazy) Tainted: [B]=BAD_PAGE Hardware name: QEMU Ubuntu 24.04 PC v2 (i440FX + PIIX, arch_caps fix, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014 Workqueue: isert_comp_wq isert_do_control_comp Call Trace: <TASK> dump_stack_lvl+0x53/0x70 print_report+0xd0/0x630 ? __pfx__raw_spin_lock_irqsave+0x10/0x10 ? _raw_spin_unlock_irqrestore+0x3e/0x70 ? isert_put_cmd+0x53d/0x620 kasan_report+0xce/0x100 ? isert_put_cmd+0x53d/0x620 isert_put_cmd+0x53d/0x620 ? isert_completion_put+0x305/0x330 ? isert_do_control_comp+0x2ef/0x310 process_one_work+0x633/0x1030 ? assign_work+0x11d/0x370 worker_thread+0x45b/0xd10 ? __pfx_worker_thread+0x10/0x10 ? __pfx_worker_thread+0x10/0x10 kthread+0x2c6/0x3b0 ? recalc_sigpending+0x15c/0x1e0 ? __pfx_kthread+0x10/0x10 ret_from_fork+0x36e/0x5a0 ? __pfx_ret_from_fork+0x10/0x10 ? __switch_to+0x572/0xdd0 ? __pfx_kthread+0x10/0x10 ret_from_fork_asm+0x1a/0x30 </TASK> Allocated by task 48: kasan_save_stack+0x33/0x60 kasan_save_track+0x14/0x30 __kasan_kmalloc+0x8f/0xa0 __kmalloc_cache_noprof+0x158/0x370 isert_cma_handler+0x1e3/0x2ae0 cma_cm_event_handler+0x3e/0x240 cma_ib_req_handler+0x17d9/0x4490 cm_process_work+0x41/0x330 cm_work_handler+0x5727/0xc160 process_one_work+0x633/0x1030 worker_thread+0x45b/0xd10 kthread+0x2c6/0x3b0 ret_from_fork+0x36e/0x5a0 ret_from_fork_asm+0x1a/0x30 Freed by task 184: kasan_save_stack+0x33/0x60 kasan_save_track+0x14/0x30 kasan_save_free_info+0x3b/0x60 __kasan_slab_free+0x43/0x70 kfree+0x121/0x380 iscsit_close_connection+0x7cf/0x1e60 iscsit_take_action_for_connection_exit+0x1b6/0x360 iscsi_target_tx_thread+0x472/0x690 kthread+0x2c6/0x3b0 ret_from_fork+0x36e/0x5a0 ret_from_fork_asm+0x1a/0x30
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.16%
- Percentil entre todas las CVEs puntuadas: 5
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/0e230917670c6e6fe3243abfa11299fcbe05b1f4
- https://git.kernel.org/stable/c/505b242d9351690d1385bbe508ab4666f60363ce
- https://git.kernel.org/stable/c/7908fbc597a694bbd99bfb59ece73bc3daded68e
- https://git.kernel.org/stable/c/7edb8a88d6c76237c8b4435765bee1009e26a50a
- https://git.kernel.org/stable/c/a8fe3dfce8c0d8a76dc3d8486a5bff5feebe156f
- https://git.kernel.org/stable/c/b96b8b3e41c308f606ffd10cfef1a7b9f97414cd
- https://git.kernel.org/stable/c/ccdb1523f12bc8a9646de65055d1aafed9e9bcc6
- https://git.kernel.org/stable/c/f5613acbe2e346d5c466ef0bd264fca936b69f82
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-98357",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "b8d26b3be8b33682cf163274ed07479a70554633",
"lessThan": "f5613acbe2e346d5c466ef0bd264fca936b69f82",
"versionType": "git"
},
{
"status": "affected",
"version": "b8d26b3be8b33682cf163274ed07479a70554633",
"lessThan": "ccdb1523f12bc8a9646de65055d1aafed9e9bcc6",
"versionType": "git"
},
{
"status": "affected",
"version": "b8d26b3be8b33682cf163274ed07479a70554633",
"lessThan": "0e230917670c6e6fe3243abfa11299fcbe05b1f4",
"versionType": "git"
},
{
"status": "affected",
"version": "b8d26b3be8b33682cf163274ed07479a70554633",
"lessThan": "505b242d9351690d1385bbe508ab4666f60363ce",
"versionType": "git"
},
{
"status": "affected",
"version": "b8d26b3be8b33682cf163274ed07479a70554633",
"lessThan": "7edb8a88d6c76237c8b4435765bee1009e26a50a",
"versionType": "git"
},
{
"status": "affected",
"version": "b8d26b3be8b33682cf163274ed07479a70554633",
"lessThan": "b96b8b3e41c308f606ffd10cfef1a7b9f97414cd",
"versionType": "git"
},
{
"status": "affected",
"version": "b8d26b3be8b33682cf163274ed07479a70554633",
"lessThan": "7908fbc597a694bbd99bfb59ece73bc3daded68e",
"versionType": "git"
},
{
"status": "affected",
"version": "b8d26b3be8b33682cf163274ed07479a70554633",
"lessThan": "a8fe3dfce8c0d8a76dc3d8486a5bff5feebe156f",
"versionType": "git"
}
],
"programFiles": [
"drivers/infiniband/ulp/isert/ib_isert.c",
"drivers/infiniband/ulp/isert/ib_isert.h"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "3.10"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "3.10",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.10.271",
"versionType": "semver",
"lessThanOrEqual": "5.10.*"
},
{
"status": "unaffected",
"version": "5.15.222",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.189",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.158",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.112",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.54",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2.8",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc4",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/infiniband/ulp/isert/ib_isert.c",
"drivers/infiniband/ulp/isert/ib_isert.h"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-10-06T09:18:29.293",
"references": [
{
"url": "https://git.kernel.org/stable/c/0e230917670c6e6fe3243abfa11299fcbe05b1f4",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/505b242d9351690d1385bbe508ab4666f60363ce",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/7908fbc597a694bbd99bfb59ece73bc3daded68e",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/7edb8a88d6c76237c8b4435765bee1009e26a50a",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/a8fe3dfce8c0d8a76dc3d8486a5bff5feebe156f",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/b96b8b3e41c308f606ffd10cfef1a7b9f97414cd",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/ccdb1523f12bc8a9646de65055d1aafed9e9bcc6",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/f5613acbe2e346d5c466ef0bd264fca936b69f82",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nIB/isert: wait for deferred control PDU completions before releasing the connection\n\nisert_send_done() hands ISTATE_SEND_TASKMGTRSP, ISTATE_SEND_REJECT and\nISTATE_SEND_TEXTRSP completions off to isert_comp_wq and returns. The work\nitem then runs isert_completion_put() -> isert_put_cmd(), which reads\nisert_conn->conn and takes conn->cmd_lock.\n\nNothing orders that work item against teardown. isert_wait_conn() queues\nisert_release_work, which frees isert_conn, and iscsit_close_connection()\nfrees the iscsit_conn right after it returns, so the queued work can run\nagainst freed memory.\n\nCount the deferred control PDU completions per connection and let\nisert_wait_conn() wait for them before the release work is queued.\n\nISTATE_SEND_LOGOUTRSP is deliberately not counted: that branch runs\niscsit_logout_post_handler(), which ends up waiting for\nconn->conn_wait_comp, and that completion is only sent by\niscsit_close_connection() after it has called iscsit_wait_conn().\nWaiting for it here would deadlock. Its wait stays the existing\nisert_wait4logout().\n\nThe splat below is from a kernel with tracing printk()s and an msleep(200)\ninjected into isert_do_control_comp() to widen the window:\n\n BUG: KASAN: slab-use-after-free in isert_put_cmd+0x53d/0x620\n Read of size 8 at addr ffff8881054f1038 by task kworker/u17:1/182\n\n CPU: 0 UID: 0 PID: 182 Comm: kworker/u17:1 Tainted: G B 7.2.0-rc5-TWIDE-gb8babf08acc7 #1 PREEMPT(lazy)\n Tainted: [B]=BAD_PAGE\n Hardware name: QEMU Ubuntu 24.04 PC v2 (i440FX + PIIX, arch_caps fix, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014\n Workqueue: isert_comp_wq isert_do_control_comp\n Call Trace:\n <TASK>\n dump_stack_lvl+0x53/0x70\n print_report+0xd0/0x630\n ? __pfx__raw_spin_lock_irqsave+0x10/0x10\n ? _raw_spin_unlock_irqrestore+0x3e/0x70\n ? isert_put_cmd+0x53d/0x620\n kasan_report+0xce/0x100\n ? isert_put_cmd+0x53d/0x620\n isert_put_cmd+0x53d/0x620\n ? isert_completion_put+0x305/0x330\n ? isert_do_control_comp+0x2ef/0x310\n process_one_work+0x633/0x1030\n ? assign_work+0x11d/0x370\n worker_thread+0x45b/0xd10\n ? __pfx_worker_thread+0x10/0x10\n ? __pfx_worker_thread+0x10/0x10\n kthread+0x2c6/0x3b0\n ? recalc_sigpending+0x15c/0x1e0\n ? __pfx_kthread+0x10/0x10\n ret_from_fork+0x36e/0x5a0\n ? __pfx_ret_from_fork+0x10/0x10\n ? __switch_to+0x572/0xdd0\n ? __pfx_kthread+0x10/0x10\n ret_from_fork_asm+0x1a/0x30\n </TASK>\n\n Allocated by task 48:\n kasan_save_stack+0x33/0x60\n kasan_save_track+0x14/0x30\n __kasan_kmalloc+0x8f/0xa0\n __kmalloc_cache_noprof+0x158/0x370\n isert_cma_handler+0x1e3/0x2ae0\n cma_cm_event_handler+0x3e/0x240\n cma_ib_req_handler+0x17d9/0x4490\n cm_process_work+0x41/0x330\n cm_work_handler+0x5727/0xc160\n process_one_work+0x633/0x1030\n worker_thread+0x45b/0xd10\n kthread+0x2c6/0x3b0\n ret_from_fork+0x36e/0x5a0\n ret_from_fork_asm+0x1a/0x30\n\n Freed by task 184:\n kasan_save_stack+0x33/0x60\n kasan_save_track+0x14/0x30\n kasan_save_free_info+0x3b/0x60\n __kasan_slab_free+0x43/0x70\n kfree+0x121/0x380\n iscsit_close_connection+0x7cf/0x1e60\n iscsit_take_action_for_connection_exit+0x1b6/0x360\n iscsi_target_tx_thread+0x472/0x690\n kthread+0x2c6/0x3b0\n ret_from_fork+0x36e/0x5a0\n ret_from_fork_asm+0x1a/0x30"
}
],
"lastModified": "2026-10-06T09:18:29.293",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}