Database/Kernel, userspace & hypervisor
Linux kernel IB/isert: deferred control PDU completions can run against a freed connection on teardown
Impact
isert_send_done() hands task-management, reject and text-response completions to isert_comp_wq and returns, with nothing ordering those work items against teardown. isert_wait_conn() queues the release work that frees isert_conn, and iscsit_close_connection() frees the iscsit_conn immediately after, so the queued work item can read isert_conn->conn and take conn->cmd_lock on freed memory - the KASAN splat in the commit shows the slab-use-after-free in isert_put_cmd(). This matters on storage nodes that export iSER targets over InfiniBand or RoCE to a GPU fleet: a connection that drops at the wrong moment corrupts kernel memory on the target, and the fabric that carries it typically crosses tenants. NVD scores it network-reachable with high attack complexity, which matches a teardown race rather than a deterministic exploit.
Who can reach it
Anyone who can open and then tear down an iSER session against the target - that is, any host on the storage fabric that the target accepts connections from. Only affects nodes running the isert target (the kernel iSCSI/iSER target stack); initiator-only and non-iSER hosts are unaffected.
What to do
Take the stable kernel fix, which counts deferred control PDU completions per connection and makes isert_wait_conn() wait for them (five stable commits listed), then reboot each target node - draining a storage target is the expensive part here, not the patch. Until then the exposure is limited by who can reach the iSER portal, so tightening fabric access to the target is the available mitigation. No fixed release number is given in the record.
References
Related entries
- Linux kernel (virt/kvm): The dirty-ring reset path bounds-checks an offset with unchecked 64-bit arithmetic, so aCVE-2026-52969 · Linux kernel (virt/kvm)High
- Linux kernel (arch/x86/kvm/svm): VMLOAD/VMSAVE executed by an L2 guest and not intercepted by L1 were emulated againstCVE-2026-43133 · Linux kernel (arch/x86/kvm/svm)High
- util-linux nsenter: --join-cgroup leaks a root-opened cgroup.procs fd into the target containerCVE-2026-78408 · util-linux nsenter (--join-cgroup descriptor leak across execve)High
- Linux kernel KVM/arm64: guest-controlled TLBI Range can overflow the hypervisor's range computationCVE-2026-89911 · Linux kernel KVM arm64 (TLBI by Range)High
- Linux kernel RDS (Reliable Datagram Sockets) net/rds/page.c - rds_page_copy_user: Straight local-to-root. RDS - theCVE-2010-3904 · Linux kernel RDS (Reliable Datagram Sockets) net/rds/page.c - rds_page_copy_userHigh
- Linux kernel KVM device assignment IOMMU path virt/kvm/iommu.c - kvm_iommu_map_pages: When an IOMMU mapping failsCVE-2014-3601 · Linux kernel KVM device assignment IOMMU path virt/kvm/iommu.c - kvm_iommu_map_pagesHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.