Database/Kernel, userspace & hypervisor
Linux kernel - LIO iSCSI target CHAP authentication, drivers/target/iscsi/iscsi_target_auth.c
Impact
Chap_server_compute_hash() allocated the client digest buffer at the hash's digest size, then passed a base64 CHAP_R response to the decoder without checking whether the input could produce more output than that. Up to 127 base64 characters decode to 95 bytes - a 63-byte overflow for SHA-256, 79 bytes for MD5 - and the existing length check fired only after the write had already happened. This is a heap overflow reached during CHAP authentication, meaning pre-authentication by definition: anyone who can open an iSCSI session to the target gets a controlled kernel heap write on the storage node. The HEX branch of the same switch already validated its length, so the bug was a straightforward omission on the base64 path.
Who can reach it
Open an iSCSI session to the LIO target and send a CHAP_R value with the '0b' base64 prefix and a long payload. No valid credentials required - the overflow happens while the target is still working out whether your credentials are valid. Reachable from any host that can reach the iSCSI port.
What to do
Host reboot / kernel upgrade on all LIO iSCSI target nodes - urgent, pre-auth, 9.8. Interim controls: restrict the iSCSI target port to known initiator addresses at the firewall and switch, and if CHAP is not required, note that disabling it does not help since the parser is reached during login negotiation. Move iSCSI targets off tenant-reachable networks. Where the iSCSI target is legacy, decommissioning it is the cleanest fix.
References
Related entries
- Linux kernel (net/tls): A particular kTLS ring state builds a scatterlist whose chain link points directly at anotherCVE-2026-64046 · Linux kernel (net/tls)Critical
- Linux kernel (net/tls): When the kTLS transmit scatterlist ring wraps, the chain link that stitches the tail back toCVE-2026-64047 · Linux kernel (net/tls)Critical
- Linux kernel mlx5_core TX timeout devlink health reporter: The TX timeout recovery handler accesses the netdev pointerCVE-2026-64122 · Linux kernel mlx5_core TX timeout devlink health reporterCritical
- Linux kernel BPF devmap: cloning fragmented XDP frames for broadcast redirect reads out of boundsCVE-2026-64355 · Linux kernel BPF devmap (XDP broadcast redirect clone path)Critical
- Linux kernel krb5 crypto: use-after-free when an async AEAD backend is bound to the enctypeCVE-2026-64439 · Linux kernel krb5 crypto helpers (rfc3961_simplified / rfc8009_aes2 AEAD paths)Critical
- Linux kernel (drivers/nvme/target): A client connected to your NVMe-oF TCP target can drive a reference-count underflowCVE-2026-64534 · Linux kernel (drivers/nvme/target)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.