« Volver al listado

CVE-2026-98358

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

IB/iser: reject a remote invalidation of an unregistered direction

A write command whose data is sent entirely as immediate data is not registered. iser_reg_mem_fastreg() takes the DMA key path and leaves rdma_reg[ISER_DIR_OUT].desc at NULL, while iser_dma_map_task_data() has already set dir[ISER_DIR_OUT].

iser_check_remote_inv() looks at dir[] alone and hands the descriptor to iser_inv_desc(), which reads desc->sig_protected. A target that answers such a command with IB_WR_SEND_WITH_INV faults the initiator. Leaving those commands unregistered is deliberate.

Leer descripción completaMostrar menos

The same function already terminates the connection when a target sends a remote invalidation the initiator did not ask for. A target that invalidates a direction that was never registered is in the same class, so give it the same answer.

Detalles técnicos trazas, registros y código del informe original
  Oops: general protection fault, probably for non-canonical address 0xdffffc0000000004: 0000 [#1] SMP KASAN NOPTI
  KASAN: null-ptr-deref in range [0x0000000000000020-0x0000000000000027]
  CPU: 0 UID: 0 PID: 40 Comm: kworker/u8:2 Not tainted 7.2.0-rc5-ISERHOST-gf5098b6bae76-dirty #3 PREEMPT(lazy)
  Hardware name: QEMU Ubuntu 24.04 PC v2 (i440FX + PIIX, arch_caps fix, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
  Workqueue: rxe_wq do_work
  RIP: 0010:iser_task_rsp+0x6d6/0xec0
  Code: 48 c1 ea 03 80 3c 02 00 0f 85 ba 06 00 00 48 8b 9b 78 01 00 00 48 b8 00 00 00 00 00 fc ff df 48 8d 7b 20 48 89 fa 48 c1 ea 03 <0f> b6 04 02 84 c0 74 06 0f 8e 76 06 00 00 80 7b 20 00 0f 84 3d 04
  RSP: 0018:ffff88811b008db8 EFLAGS: 00010202
  RAX: dffffc0000000000 RBX: 0000000000000000 RCX: 0000000000001848
  RDX: 0000000000000004 RSI: 1ffff11021587b12 RDI: 0000000000000020
  RBP: ffff88810adc1ae4 R08: ffff888109b7f860 R09: ffffffff90a922c0
  R10: ffff88810adc1a1c R11: 000000000000003c R12: ffff888109b7f800
  R13: ffff88810adc1acc R14: ffff888109b7f820 R15: 0000000000000000
  FS:  0000000000000000(0000) GS:ffff88818a676000(0000) knlGS:0000000000000000
  CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
  CR2: 00000000005afe2b CR3: 000000010af23005 CR4: 0000000000770ef0
  PKRU: 55555554
  Call Trace:
   <IRQ>
   __ib_process_cq+0xe1/0x390
   ib_poll_handler+0x6e/0x200
   irq_poll_softirq+0x1df/0x480
   ? clockevents_program_event+0x2ba/0x860
   ? __pfx_irq_poll_softirq+0x10/0x10
   handle_softirqs+0x18e/0x590
   ? __pfx_handle_softirqs+0x10/0x10
   ? __hrtimer_rearm_deferred+0x156/0x450
   do_softirq+0x3b/0x60
   </IRQ>
   <TASK>
   __local_bh_enable_ip+0x61/0x70
   __alloc_skb+0x732/0x890
   ? _raw_spin_lock_irqsave+0x85/0xe0
   ? __pfx___alloc_skb+0x10/0x10
   ? _raw_read_unlock_irqrestore+0x16/0x50
   rxe_init_packet+0x16b/0x4f0
   prepare_ack_packet+0xb8/0x830
   rxe_receiver+0x499/0x9980
   ? __pfx_rxe_receiver+0x10/0x10
   ? rxe_completer+0x29e5/0x38c0
   ? hrtimer_start_range_ns_common+0x75f/0x1730
   ? hrtimer_start_range_ns+0xa6/0x2c0
   ? __pfx__raw_spin_lock_irqsave+0x10/0x10
   ? __pfx_rxe_receiver+0x10/0x10
   do_work+0x144/0x470
   process_one_work+0x633/0x1030
   ? assign_work+0x11d/0x370
   worker_thread+0x45b/0xd10
   ? __pfx_worker_thread+0x10/0x10
   kthread+0x2c6/0x3b0
   ? recalc_sigpending+0x15c/0x1e0
   ? __pfx_kthread+0x10/0x10
   ret_from_fork+0x36e/0x5a0
   ? __pfx_ret_from_fork+0x10/0x10
   ? __switch_to+0x572/0xdd0
   ? __pfx_kthread+0x10/0x10
   ret_from_fork_asm+0x1a/0x30
   </TASK>
  Modules linked in:
  ---[ end trace 0000000000000000 ]---

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-98358",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "59caaed7a72a0e3750dfb84636dae6b781559310",
              "lessThan": "198e4db9add54a50cce60a5d80b8f0ee5456b65a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "59caaed7a72a0e3750dfb84636dae6b781559310",
              "lessThan": "b9e37452915feaa8422af87dea5d0c16a7d1ff13",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "59caaed7a72a0e3750dfb84636dae6b781559310",
              "lessThan": "19ddd4af7fce9200e70882f622011e9dd130f427",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "59caaed7a72a0e3750dfb84636dae6b781559310",
              "lessThan": "9d145a2d8d6f8f2cc460b80df41870819048f2a0",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "59caaed7a72a0e3750dfb84636dae6b781559310",
              "lessThan": "b4d278c91209931199db9c0836dc2e21a7593dad",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "59caaed7a72a0e3750dfb84636dae6b781559310",
              "lessThan": "6ed3ebaff3345837f0528d85bd39ce573c7b9a41",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "59caaed7a72a0e3750dfb84636dae6b781559310",
              "lessThan": "ceecf3f9c322fc6937a66682942a26ad13a34a07",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "59caaed7a72a0e3750dfb84636dae6b781559310",
              "lessThan": "d85f0f0a7c85756fc992c70d869706f19dac9259",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/infiniband/ulp/iser/iser_initiator.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4.5"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "4.5",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.271",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.222",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.189",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.158",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.112",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.54",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.8",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc4",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/infiniband/ulp/iser/iser_initiator.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-10-06T09:18:29.477",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/198e4db9add54a50cce60a5d80b8f0ee5456b65a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/19ddd4af7fce9200e70882f622011e9dd130f427",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/6ed3ebaff3345837f0528d85bd39ce573c7b9a41",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/9d145a2d8d6f8f2cc460b80df41870819048f2a0",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/b4d278c91209931199db9c0836dc2e21a7593dad",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/b9e37452915feaa8422af87dea5d0c16a7d1ff13",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/ceecf3f9c322fc6937a66682942a26ad13a34a07",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/d85f0f0a7c85756fc992c70d869706f19dac9259",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nIB/iser: reject a remote invalidation of an unregistered direction\n\nA write command whose data is sent entirely as immediate data is not\nregistered.  iser_reg_mem_fastreg() takes the DMA key path and leaves\nrdma_reg[ISER_DIR_OUT].desc at NULL, while iser_dma_map_task_data() has\nalready set dir[ISER_DIR_OUT].\n\niser_check_remote_inv() looks at dir[] alone and hands the descriptor to\niser_inv_desc(), which reads desc->sig_protected.  A target that answers\nsuch a command with IB_WR_SEND_WITH_INV faults the initiator.\nLeaving those commands unregistered is deliberate.\n\nThe same function already terminates the connection when a target sends\na remote invalidation the initiator did not ask for.  A target that\ninvalidates a direction that was never registered is in the same class,\nso give it the same answer.\n\n  Oops: general protection fault, probably for non-canonical address 0xdffffc0000000004: 0000 [#1] SMP KASAN NOPTI\n  KASAN: null-ptr-deref in range [0x0000000000000020-0x0000000000000027]\n  CPU: 0 UID: 0 PID: 40 Comm: kworker/u8:2 Not tainted 7.2.0-rc5-ISERHOST-gf5098b6bae76-dirty #3 PREEMPT(lazy)\n  Hardware name: QEMU Ubuntu 24.04 PC v2 (i440FX + PIIX, arch_caps fix, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014\n  Workqueue: rxe_wq do_work\n  RIP: 0010:iser_task_rsp+0x6d6/0xec0\n  Code: 48 c1 ea 03 80 3c 02 00 0f 85 ba 06 00 00 48 8b 9b 78 01 00 00 48 b8 00 00 00 00 00 fc ff df 48 8d 7b 20 48 89 fa 48 c1 ea 03 <0f> b6 04 02 84 c0 74 06 0f 8e 76 06 00 00 80 7b 20 00 0f 84 3d 04\n  RSP: 0018:ffff88811b008db8 EFLAGS: 00010202\n  RAX: dffffc0000000000 RBX: 0000000000000000 RCX: 0000000000001848\n  RDX: 0000000000000004 RSI: 1ffff11021587b12 RDI: 0000000000000020\n  RBP: ffff88810adc1ae4 R08: ffff888109b7f860 R09: ffffffff90a922c0\n  R10: ffff88810adc1a1c R11: 000000000000003c R12: ffff888109b7f800\n  R13: ffff88810adc1acc R14: ffff888109b7f820 R15: 0000000000000000\n  FS:  0000000000000000(0000) GS:ffff88818a676000(0000) knlGS:0000000000000000\n  CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n  CR2: 00000000005afe2b CR3: 000000010af23005 CR4: 0000000000770ef0\n  PKRU: 55555554\n  Call Trace:\n   <IRQ>\n   __ib_process_cq+0xe1/0x390\n   ib_poll_handler+0x6e/0x200\n   irq_poll_softirq+0x1df/0x480\n   ? clockevents_program_event+0x2ba/0x860\n   ? __pfx_irq_poll_softirq+0x10/0x10\n   handle_softirqs+0x18e/0x590\n   ? __pfx_handle_softirqs+0x10/0x10\n   ? __hrtimer_rearm_deferred+0x156/0x450\n   do_softirq+0x3b/0x60\n   </IRQ>\n   <TASK>\n   __local_bh_enable_ip+0x61/0x70\n   __alloc_skb+0x732/0x890\n   ? _raw_spin_lock_irqsave+0x85/0xe0\n   ? __pfx___alloc_skb+0x10/0x10\n   ? _raw_read_unlock_irqrestore+0x16/0x50\n   rxe_init_packet+0x16b/0x4f0\n   prepare_ack_packet+0xb8/0x830\n   rxe_receiver+0x499/0x9980\n   ? __pfx_rxe_receiver+0x10/0x10\n   ? rxe_completer+0x29e5/0x38c0\n   ? hrtimer_start_range_ns_common+0x75f/0x1730\n   ? hrtimer_start_range_ns+0xa6/0x2c0\n   ? __pfx__raw_spin_lock_irqsave+0x10/0x10\n   ? __pfx_rxe_receiver+0x10/0x10\n   do_work+0x144/0x470\n   process_one_work+0x633/0x1030\n   ? assign_work+0x11d/0x370\n   worker_thread+0x45b/0xd10\n   ? __pfx_worker_thread+0x10/0x10\n   kthread+0x2c6/0x3b0\n   ? recalc_sigpending+0x15c/0x1e0\n   ? __pfx_kthread+0x10/0x10\n   ret_from_fork+0x36e/0x5a0\n   ? __pfx_ret_from_fork+0x10/0x10\n   ? __switch_to+0x572/0xdd0\n   ? __pfx_kthread+0x10/0x10\n   ret_from_fork_asm+0x1a/0x30\n   </TASK>\n  Modules linked in:\n  ---[ end trace 0000000000000000 ]---"
    }
  ],
  "lastModified": "2026-10-06T09:18:29.477",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}