Database/Firmware, BMC & network fabric
Linux kernel - iSER (iSCSI Extensions for RDMA) target, drivers/infiniband/ulp/isert/ib_isert.c: The iSER target
Impact
The iSER target accepted login PDUs shorter than ISER_HEADERS_LEN and parsed them anyway, giving out-of-bounds access in the kernel before any authentication has occurred. Login is by definition the pre-auth surface, so anyone who can reach the iSER target port gets remote kernel compromise on the storage node with no credentials at all. A storage node in a GPU cluster typically mounts and serves many tenants' volumes, so compromising it is equivalent to compromising every dataset it fronts.
Who can reach it
Connect to the iSER target and send a truncated login PDU. Fully pre-authentication, no valid initiator identity required, reachable from anywhere on the storage fabric. If the storage fabric is not separated from the tenant fabric - a common shortcut - this is reachable from tenant workloads directly.
What to do
Host reboot / kernel upgrade on iSER target nodes, treated as urgent given it is pre-auth and scored 9.8. Immediate config controls while you schedule the reboot: restrict the iSER/iSCSI target port to known initiator addresses at the switch and host firewall, and place storage targets on a fabric partition tenants cannot reach. If iSER is unused, unload ib_isert and disable the target configuration.
References
Related entries
- uefi-firmware-parser: unvalidated bit lengths in MakeTable() smash the stack on crafted firmwareCVE-2026-54333 · uefi-firmware-parser Tiano decompressor (MakeTable bit-length validation)Critical
- uefi-firmware-parser: ReadCLen() overruns the 510-entry mCLen heap array on crafted firmwareCVE-2026-54334 · uefi-firmware-parser Tiano decompressor (ReadCLen mCLen bounds)Critical
- Dell SmartFabric OS10 before 10.6.1.3: session fixation lets a remote unauthenticated attacker steal a sessionCVE-2026-63695 · Dell SmartFabric OS10 (session handling in the management interface)Critical
- Linux kernel (drivers/infiniband/ulp/rtrs): On the RTRS server, a failure while publishing a new session's sysfsCVE-2026-64033 · Linux kernel (drivers/infiniband/ulp/rtrs)Critical
- Linux kernel - RDMA/siw (soft-iWARP) MPA framing, drivers/infiniband/sw/siw/siw_qp_rx.c: The siw receive path decodesCVE-2026-64102 · Linux kernel - RDMA/siw (soft-iWARP) MPA framing, drivers/infiniband/sw/siw/siw_qp_rx.cCritical
- Linux kernel - RDMA/siw (soft-iWARP), drivers/infiniband/sw/siw/siw_qp_rx.c: Siw places inbound Read Response segmentsCVE-2026-64268 · Linux kernel - RDMA/siw (soft-iWARP), drivers/infiniband/sw/siw/siw_qp_rx.cCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.