GPU VulnDB

Database/Kernel, userspace & hypervisor

Linux kernel SCSI core: unvalidated MODE SENSE lengths leak stack memory to the storage device

UnscoredCVE-2026-98232Kernel, userspace & hypervisorcurated

Impact

scsi_cdl_enable() trusts the length fields a target returns from MODE SENSE when locating the ATA feature page in a 64-byte stack buffer. A target that reports a total length shorter than its own mode header and block descriptors makes the unsigned subtraction wrap and buf_data point past the buffer, so the kernel clears bits in a device-chosen out-of-bounds stack byte and then copies up to 64 bytes of adjacent kernel stack into the outgoing MODE SELECT payload - handing stack contents, including pointers useful for defeating KASLR, to whatever is on the other end of the bus. The path runs during automatic enumeration: no mount and no userspace access to the block device is required. The reporter demonstrated it with a Raw Gadget USB device that claims to be an ATA device advertising CDL support.

Who can reach it

Requires a malicious or emulated storage device to be attached and enumerated - physical USB access to the node, or control of virtual media presented to the host, for example a mapped USB/CD image over the BMC's Redfish or KVM interface. No host authentication and no logged-in user are needed once the device is attached.

What to do

Take the stable kernel update that caps the available length to the buffer size and validates the mode header and block descriptor lengths, then drain and reboot each node. Until then, treat BMC virtual-media mapping as a privileged operation and keep the management VLAN closed, and keep physical USB ports on production nodes disabled or restricted. The record names only the stable commits, not a fixed release version.

References

Related entries

All Kernel, userspace & hypervisor entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.