Database/Kernel, userspace & hypervisor
Linux kernel libiscsi: out-of-bounds read leaks stale connection data into the SCSI sense buffer
Impact
iscsi_scsi_cmd_rsp() checks the received data segment length against the sense length without accounting for the 2-byte sense-length prefix, so a target that returns datalen == senselen makes the copy read up to two bytes past the received data. Those bytes are stale conn->data contents from earlier traffic on the same iSCSI connection, and they are handed to userspace in the command's sense buffer. The leak is small and bounded — two bytes of adjacent connection buffer per response — but it crosses from kernel connection state into whatever process issued the SCSI command. Only nodes that mount storage over the iSCSI initiator are affected; a GPU node with no iSCSI-backed volumes never reaches this code.
Who can reach it
Requires control over the responses of an iSCSI target the node's initiator is connected to — a malicious or compromised target, or an attacker able to inject responses into an unauthenticated iSCSI session on the storage network. No credentials on the GPU node itself are needed.
What to do
The fix is merged upstream and backported across stable branches (five stable commits are listed on the record). Update the host kernel from your distribution and reboot each initiator node; there is no runtime mitigation short of not using the iSCSI initiator. The record does not name distribution package versions, only the stable commits.
References
Related entries
- Linux kernel LIO iblock: missing PR handler checks let PERSISTENT RESERVE OUT NULL-deref the kernelCVE-2026-80691 · Linux kernel SCSI target (LIO) iblock backend, PERSISTENT RESERVE OUT handlingHigh
- Linux kernel iomap: ioend splitting draws from its own exhausted bio_set and deadlocks writebackCVE-2026-80720 · Linux kernel iomap writeback (iomap_split_ioend sharing iomap_ioend_bioset)High
- Linux kernel crypto/krb5: derived Kerberos keys left in freed slab memoryCVE-2026-80924 · Linux kernel crypto/krb5 (derived key buffers for RPCSEC_GSS)High
- Linux kernel ntb_transport: oversized transmit buffers leak skbs until the host runs out of memoryCVE-2026-80987 · Linux kernel NTB ntb_transport / ntb_netdev (oversized TX buffer skb leak)High
- OpenSSL 4.0: use-after-free in the X.509 extension cache crashes multi-threaded TLS peersCVE-2026-84783 · OpenSSL 4.0 X.509 extension cache (concurrent X509 use)High
- OpenSSL QUIC: unthrottled RETIRE_CONNECTION_ID backlog lets a peer force ~400MB of allocationCVE-2026-84784 · OpenSSL QUIC stack (NEW_CONNECTION_ID / RETIRE_CONNECTION_ID handling)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.