{"api_version":"1","generated_at":"2026-10-01T18:35:11+00:00","cve":"CVE-2026-90414","urls":{"html":"https://cve.report/CVE-2026-90414","api":"https://cve.report/api/cve/CVE-2026-90414.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-90414","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-90414"},"summary":{"title":"IB/isert: reject PDUs declaring more data than was received","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nIB/isert: reject PDUs declaring more data than was received\n\nisert_recv_done() hands each received PDU to the opcode handlers without\never looking at wc->byte_len, the number of bytes the HCA actually placed\nin the receive descriptor. The handlers then copy that many bytes - the\ndata-segment length the initiator declared in the BHS\n(ntoh24(hdr->dlength), via the derived unsol_data_len / imm_data_len) -\nout of the fixed-size descriptor:\n\n  isert_handle_iscsi_dataout():\n        sg_copy_from_buffer(sg_start, sg_nents, isert_get_data(rx_desc),\n                            unsol_data_len);\n  isert_handle_scsi_cmd():\n        sg_copy_from_buffer(cmd->se_cmd.t_data_sg, sg_nents,\n                            isert_get_data(rx_desc), imm_data_len);\n\nBecause the declared length is never checked against wc->byte_len, an\ninitiator can declare a data segment larger than the bytes it actually\nsent (and larger than the descriptor) and cause an out-of-bounds read of\nthe receive buffer.\n\nNothing upstream of isert closes this door:\n\n  - __iscsit_check_dataout_hdr() bounds the inbound payload against\n    conn_ops->MaxXmitDataSegmentLength (MXDSL) - a transmit parameter,\n    used here for the inbound check.\n  - iscsi_set_connection_parameters() sets\n    ops->MaxXmitDataSegmentLength = ops->TargetRecvDataSegmentLength;\n    and TARGETRECVDATASEGMENTLENGTH is absent from the min()-clamp list in\n    iscsi_check_acceptor_state(), so the value the initiator declares is\n    adopted verbatim (type range 512..16777215). The initiator effectively\n    raises its own ceiling.\n  - isert never clamps the negotiated value to its own fixed receive\n    descriptor (ISER_RX_SIZE, 9216 bytes), so the target core's bound and\n    the descriptor size are unrelated.\n\nThe imm_data_len == data_len path is more than an over-read: it aliases\nthe receive descriptor via sg_set_buf() and passes it to the backend as\nthe data source for the SCSI WRITE, so an over-declared length causes heap\ncontents past the descriptor to be written through the backend to the\nbacking store. The backend is the victim of the oversized scatterlist\nisert hands it, not the cause; no read-back of the written bytes was\ndemonstrated.\n\nTrigger: after login completes (full feature phase), an initiator that has\ndeclared a large TargetRecvDataSegmentLength and a FirstBurstLength that\npermits unsolicited/immediate data sends a PDU whose declared data-segment\nlength exceeds what was received. With KASAN:\n\n  BUG: KASAN: slab-out-of-bounds in sg_copy_buffer+0x150/0x1c0\n  Read of size 4096 at addr ffff888109720800 by task kworker/1:0H/25\n  Workqueue: ib-comp-wq ib_cq_poll_work\n  Call Trace:\n   sg_copy_buffer+0x150/0x1c0\n   isert_recv_done+0xba6/0x2390\n   __ib_process_cq+0xe1/0x390\n   ib_cq_poll_work+0x46/0x150\n\nisert_recv_done+0xba6 resolves to isert_handle_iscsi_dataout()\n(ib_isert.c:1160), inlined through isert_rx_opcode().\n\nValidate wc->byte_len against the framing in isert_recv_done() before the\nPDU reaches any handler, and reinstate the connection if it is short.\nBecause the test compares without subtracting the header length, it also\nrejects PDUs shorter than the iSER and iSCSI headers, which would otherwise\nbe parsed out of stale descriptor contents. The login handler rejects PDUs\nshorter than ISER_HEADERS_LEN (commit 29e7b925ae6d (\"IB/isert: Reject login\nPDUs shorter than ISER_HEADERS_LEN\")) but does not bound the declared\nlength either; that is fixed in the next patch. The data handlers had no\nlength check at all.\n\nisert reads the data segment from a fixed offset: isert_get_data()\nreturns the iSER header plus ISER_HEADERS_LEN and makes no adjustment for\nan AHS.  The bytes the handlers touch are therefore exactly\n[ISER_HEADERS_LEN, ISER_HEADERS_LEN + dlength), and comparing that sum\nagainst wc->byte_len bounds precisely the region that is read.  An AHS\nterm would only make the test stricter without bounding anything furth\n---truncated---","state":"PUBLISHED","assigner":"Linux","published_at":"2026-09-17 17:17:43","updated_at":"2026-09-18 18:17:58"},"problem_types":[],"metrics":[{"version":"3.1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","score":"9.1","severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","baseScore":9.1,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"9.1","severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","data":{"baseScore":9.1,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","version":"3.1"}}],"references":[{"url":"https://git.kernel.org/stable/c/2a6b8f88fb7ee51714a1922a039225bdcaf12855","name":"https://git.kernel.org/stable/c/2a6b8f88fb7ee51714a1922a039225bdcaf12855","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/957f92ea4022fb6af4618271615a2a21a7b5bef9","name":"https://git.kernel.org/stable/c/957f92ea4022fb6af4618271615a2a21a7b5bef9","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/bc58e9d3dc560220c57b8bdfc12af0cff1c8a43d","name":"https://git.kernel.org/stable/c/bc58e9d3dc560220c57b8bdfc12af0cff1c8a43d","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/cf36fa5357a2fb25776a568d13a3653da7d99bcb","name":"https://git.kernel.org/stable/c/cf36fa5357a2fb25776a568d13a3653da7d99bcb","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/b4706722ed3ea72882b3c986a19b4a1ba66384c4","name":"https://git.kernel.org/stable/c/b4706722ed3ea72882b3c986a19b4a1ba66384c4","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/274b1ad7e78338710864c4b4235bb1ce7e7107f9","name":"https://git.kernel.org/stable/c/274b1ad7e78338710864c4b4235bb1ce7e7107f9","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/352dc85324b29f5c85876f2666f3158b645e3f18","name":"https://git.kernel.org/stable/c/352dc85324b29f5c85876f2666f3158b645e3f18","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/39da0b7e1f530347d284cebcfc5b5afa90a173bf","name":"https://git.kernel.org/stable/c/39da0b7e1f530347d284cebcfc5b5afa90a173bf","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-90414","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-90414","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected b8d26b3be8b33682cf163274ed07479a70554633 b4706722ed3ea72882b3c986a19b4a1ba66384c4 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected b8d26b3be8b33682cf163274ed07479a70554633 bc58e9d3dc560220c57b8bdfc12af0cff1c8a43d git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected b8d26b3be8b33682cf163274ed07479a70554633 274b1ad7e78338710864c4b4235bb1ce7e7107f9 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected b8d26b3be8b33682cf163274ed07479a70554633 2a6b8f88fb7ee51714a1922a039225bdcaf12855 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected b8d26b3be8b33682cf163274ed07479a70554633 39da0b7e1f530347d284cebcfc5b5afa90a173bf git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected b8d26b3be8b33682cf163274ed07479a70554633 cf36fa5357a2fb25776a568d13a3653da7d99bcb git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected b8d26b3be8b33682cf163274ed07479a70554633 352dc85324b29f5c85876f2666f3158b645e3f18 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected b8d26b3be8b33682cf163274ed07479a70554633 957f92ea4022fb6af4618271615a2a21a7b5bef9 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 3.10","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 3.10 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 5.10.270 5.10.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 5.15.221 5.15.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.1.188 6.1.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.6.157 6.6.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.12.110 6.12.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.52 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2.6 7.2.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.3-rc1 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"90414","cve":"CVE-2026-90414","epss":"0.005210000","percentile":"0.430420000","score_date":"2026-09-21","updated_at":"2026-09-22 00:03:18"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["drivers/infiniband/ulp/isert/ib_isert.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"b4706722ed3ea72882b3c986a19b4a1ba66384c4","status":"affected","version":"b8d26b3be8b33682cf163274ed07479a70554633","versionType":"git"},{"lessThan":"bc58e9d3dc560220c57b8bdfc12af0cff1c8a43d","status":"affected","version":"b8d26b3be8b33682cf163274ed07479a70554633","versionType":"git"},{"lessThan":"274b1ad7e78338710864c4b4235bb1ce7e7107f9","status":"affected","version":"b8d26b3be8b33682cf163274ed07479a70554633","versionType":"git"},{"lessThan":"2a6b8f88fb7ee51714a1922a039225bdcaf12855","status":"affected","version":"b8d26b3be8b33682cf163274ed07479a70554633","versionType":"git"},{"lessThan":"39da0b7e1f530347d284cebcfc5b5afa90a173bf","status":"affected","version":"b8d26b3be8b33682cf163274ed07479a70554633","versionType":"git"},{"lessThan":"cf36fa5357a2fb25776a568d13a3653da7d99bcb","status":"affected","version":"b8d26b3be8b33682cf163274ed07479a70554633","versionType":"git"},{"lessThan":"352dc85324b29f5c85876f2666f3158b645e3f18","status":"affected","version":"b8d26b3be8b33682cf163274ed07479a70554633","versionType":"git"},{"lessThan":"957f92ea4022fb6af4618271615a2a21a7b5bef9","status":"affected","version":"b8d26b3be8b33682cf163274ed07479a70554633","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["drivers/infiniband/ulp/isert/ib_isert.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"3.10"},{"lessThan":"3.10","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"5.10.*","status":"unaffected","version":"5.10.270","versionType":"semver"},{"lessThanOrEqual":"5.15.*","status":"unaffected","version":"5.15.221","versionType":"semver"},{"lessThanOrEqual":"6.1.*","status":"unaffected","version":"6.1.188","versionType":"semver"},{"lessThanOrEqual":"6.6.*","status":"unaffected","version":"6.6.157","versionType":"semver"},{"lessThanOrEqual":"6.12.*","status":"unaffected","version":"6.12.110","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.52","versionType":"semver"},{"lessThanOrEqual":"7.2.*","status":"unaffected","version":"7.2.6","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.3-rc1","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"5.10.270","versionStartIncluding":"3.10","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"5.15.221","versionStartIncluding":"3.10","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.1.188","versionStartIncluding":"3.10","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.6.157","versionStartIncluding":"3.10","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.12.110","versionStartIncluding":"3.10","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.52","versionStartIncluding":"3.10","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2.6","versionStartIncluding":"3.10","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.3-rc1","versionStartIncluding":"3.10","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nIB/isert: reject PDUs declaring more data than was received\n\nisert_recv_done() hands each received PDU to the opcode handlers without\never looking at wc->byte_len, the number of bytes the HCA actually placed\nin the receive descriptor. The handlers then copy that many bytes - the\ndata-segment length the initiator declared in the BHS\n(ntoh24(hdr->dlength), via the derived unsol_data_len / imm_data_len) -\nout of the fixed-size descriptor:\n\n  isert_handle_iscsi_dataout():\n        sg_copy_from_buffer(sg_start, sg_nents, isert_get_data(rx_desc),\n                            unsol_data_len);\n  isert_handle_scsi_cmd():\n        sg_copy_from_buffer(cmd->se_cmd.t_data_sg, sg_nents,\n                            isert_get_data(rx_desc), imm_data_len);\n\nBecause the declared length is never checked against wc->byte_len, an\ninitiator can declare a data segment larger than the bytes it actually\nsent (and larger than the descriptor) and cause an out-of-bounds read of\nthe receive buffer.\n\nNothing upstream of isert closes this door:\n\n  - __iscsit_check_dataout_hdr() bounds the inbound payload against\n    conn_ops->MaxXmitDataSegmentLength (MXDSL) - a transmit parameter,\n    used here for the inbound check.\n  - iscsi_set_connection_parameters() sets\n    ops->MaxXmitDataSegmentLength = ops->TargetRecvDataSegmentLength;\n    and TARGETRECVDATASEGMENTLENGTH is absent from the min()-clamp list in\n    iscsi_check_acceptor_state(), so the value the initiator declares is\n    adopted verbatim (type range 512..16777215). The initiator effectively\n    raises its own ceiling.\n  - isert never clamps the negotiated value to its own fixed receive\n    descriptor (ISER_RX_SIZE, 9216 bytes), so the target core's bound and\n    the descriptor size are unrelated.\n\nThe imm_data_len == data_len path is more than an over-read: it aliases\nthe receive descriptor via sg_set_buf() and passes it to the backend as\nthe data source for the SCSI WRITE, so an over-declared length causes heap\ncontents past the descriptor to be written through the backend to the\nbacking store. The backend is the victim of the oversized scatterlist\nisert hands it, not the cause; no read-back of the written bytes was\ndemonstrated.\n\nTrigger: after login completes (full feature phase), an initiator that has\ndeclared a large TargetRecvDataSegmentLength and a FirstBurstLength that\npermits unsolicited/immediate data sends a PDU whose declared data-segment\nlength exceeds what was received. With KASAN:\n\n  BUG: KASAN: slab-out-of-bounds in sg_copy_buffer+0x150/0x1c0\n  Read of size 4096 at addr ffff888109720800 by task kworker/1:0H/25\n  Workqueue: ib-comp-wq ib_cq_poll_work\n  Call Trace:\n   sg_copy_buffer+0x150/0x1c0\n   isert_recv_done+0xba6/0x2390\n   __ib_process_cq+0xe1/0x390\n   ib_cq_poll_work+0x46/0x150\n\nisert_recv_done+0xba6 resolves to isert_handle_iscsi_dataout()\n(ib_isert.c:1160), inlined through isert_rx_opcode().\n\nValidate wc->byte_len against the framing in isert_recv_done() before the\nPDU reaches any handler, and reinstate the connection if it is short.\nBecause the test compares without subtracting the header length, it also\nrejects PDUs shorter than the iSER and iSCSI headers, which would otherwise\nbe parsed out of stale descriptor contents. The login handler rejects PDUs\nshorter than ISER_HEADERS_LEN (commit 29e7b925ae6d (\"IB/isert: Reject login\nPDUs shorter than ISER_HEADERS_LEN\")) but does not bound the declared\nlength either; that is fixed in the next patch. The data handlers had no\nlength check at all.\n\nisert reads the data segment from a fixed offset: isert_get_data()\nreturns the iSER header plus ISER_HEADERS_LEN and makes no adjustment for\nan AHS.  The bytes the handlers touch are therefore exactly\n[ISER_HEADERS_LEN, ISER_HEADERS_LEN + dlength), and comparing that sum\nagainst wc->byte_len bounds precisely the region that is read.  An AHS\nterm would only make the test stricter without bounding anything furth\n---truncated---"}],"metrics":[{"cvssV3_1":{"baseScore":9.1,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","version":"3.1"},"scenarios":[{"lang":"en","value":"AV:N - The attacker-controlled length is ntoh24(hdr->dlength) in the iSCSI BHS of an RDMA SEND consumed by isert_recv_done(); isert_handle_iscsi_dataout(), isert_handle_scsi_cmd() and isert_handle_text_cmd() then copy that many bytes from the receive descriptor. ib_isert listens via rdma_bind_addr()/rdma_listen() on RDMA_PS_TCP (RoCEv2/iWARP), so that PDU is supplied by a remote initiator on a routable IP fabric.\nAC:L - After login the initiator sends a PDU whose BHS dlength exceeds wc->byte_len. isert_handle_text_cmd() memcpy()s that length from isert_get_data(rx_desc), and isert_handle_iscsi_dataout()/isert_handle_scsi_cmd() pass it to sg_copy_from_buffer(); on a Normal session the initiator also raises TargetRecvDataSegmentLength, which iscsi_check_acceptor_state() adopts as MaxXmitDataSegmentLength. No race is involved.\nPR:N - isert_recv_done() runs in full-feature phase, but iscsit_load_discovery_tpg() defaults discovery_tpg authentication=0 (AuthMethod=CHAP,None). iscsi_target_locate_portal() attaches that TPG for SessionType=Discovery on the isert NP, and isert_rx_opcode() then delivers ISCSI_OP_TEXT to isert_handle_text_cmd() with no credentials.\nUI:N - The remote initiator completes iSER login and posts the malformed PDU; ib_cq_poll_work on ib-comp-wq invokes isert_recv_done() with no local user or administrator action.\nS:U - The heap over-read and oops stay in the host kernel that implements ib_isert and LIO; this is not a guest-to-host, IOMMU, or other cross-authority impact.\nC:H - isert_handle_text_cmd() memcpy()s ntoh24(dlength) bytes from isert_get_data() inside the 9216-byte iser_rx_desc.buf; discovery MaxXmitDataSegmentLength defaults to 262144 and a Normal session can raise TargetRecvDataSegmentLength to 16MB, so the copy over-reads far past the descriptor. isert_handle_scsi_cmd() sg_set_buf() can also feed those heap bytes to a SCSI WRITE.\nI:N - sg_copy_from_buffer() and the text memcpy read from the receive descriptor into a destination sized for the declared length (t_data_sg from transport_generic_new_cmd(), or kzalloc(payload_length)); they do not write past kernel objects. sg_set_buf() only over-reads heap as the SCSI WRITE source.\nA:H - Copying 256KB or more from a fixed ISER_RX_SIZE (9216) descriptor is a slab-out-of-bounds read; the commit's KASAN report is BUG in sg_copy_buffer from isert_handle_iscsi_dataout(), and an over-read that leaves the rx_descs allocation oopses the target."}]}],"providerMetadata":{"dateUpdated":"2026-09-18T17:55:15.883Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/b4706722ed3ea72882b3c986a19b4a1ba66384c4"},{"url":"https://git.kernel.org/stable/c/bc58e9d3dc560220c57b8bdfc12af0cff1c8a43d"},{"url":"https://git.kernel.org/stable/c/274b1ad7e78338710864c4b4235bb1ce7e7107f9"},{"url":"https://git.kernel.org/stable/c/2a6b8f88fb7ee51714a1922a039225bdcaf12855"},{"url":"https://git.kernel.org/stable/c/39da0b7e1f530347d284cebcfc5b5afa90a173bf"},{"url":"https://git.kernel.org/stable/c/cf36fa5357a2fb25776a568d13a3653da7d99bcb"},{"url":"https://git.kernel.org/stable/c/352dc85324b29f5c85876f2666f3158b645e3f18"},{"url":"https://git.kernel.org/stable/c/957f92ea4022fb6af4618271615a2a21a7b5bef9"}],"title":"IB/isert: reject PDUs declaring more data than was received","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-90414","datePublished":"2026-09-17T16:09:40.045Z","dateReserved":"2026-09-11T19:38:34.813Z","dateUpdated":"2026-09-18T17:55:15.883Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-17 17:17:43","lastModifiedDate":"2026-09-18 18:17:58","problem_types":[],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","baseScore":9.1,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.2}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"90414","Ordinal":"1","Title":"IB/isert: reject PDUs declaring more data than was received","CVE":"CVE-2026-90414","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"90414","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nIB/isert: reject PDUs declaring more data than was received\n\nisert_recv_done() hands each received PDU to the opcode handlers without\never looking at wc->byte_len, the number of bytes the HCA actually placed\nin the receive descriptor. The handlers then copy that many bytes - the\ndata-segment length the initiator declared in the BHS\n(ntoh24(hdr->dlength), via the derived unsol_data_len / imm_data_len) -\nout of the fixed-size descriptor:\n\n  isert_handle_iscsi_dataout():\n        sg_copy_from_buffer(sg_start, sg_nents, isert_get_data(rx_desc),\n                            unsol_data_len);\n  isert_handle_scsi_cmd():\n        sg_copy_from_buffer(cmd->se_cmd.t_data_sg, sg_nents,\n                            isert_get_data(rx_desc), imm_data_len);\n\nBecause the declared length is never checked against wc->byte_len, an\ninitiator can declare a data segment larger than the bytes it actually\nsent (and larger than the descriptor) and cause an out-of-bounds read of\nthe receive buffer.\n\nNothing upstream of isert closes this door:\n\n  - __iscsit_check_dataout_hdr() bounds the inbound payload against\n    conn_ops->MaxXmitDataSegmentLength (MXDSL) - a transmit parameter,\n    used here for the inbound check.\n  - iscsi_set_connection_parameters() sets\n    ops->MaxXmitDataSegmentLength = ops->TargetRecvDataSegmentLength;\n    and TARGETRECVDATASEGMENTLENGTH is absent from the min()-clamp list in\n    iscsi_check_acceptor_state(), so the value the initiator declares is\n    adopted verbatim (type range 512..16777215). The initiator effectively\n    raises its own ceiling.\n  - isert never clamps the negotiated value to its own fixed receive\n    descriptor (ISER_RX_SIZE, 9216 bytes), so the target core's bound and\n    the descriptor size are unrelated.\n\nThe imm_data_len == data_len path is more than an over-read: it aliases\nthe receive descriptor via sg_set_buf() and passes it to the backend as\nthe data source for the SCSI WRITE, so an over-declared length causes heap\ncontents past the descriptor to be written through the backend to the\nbacking store. The backend is the victim of the oversized scatterlist\nisert hands it, not the cause; no read-back of the written bytes was\ndemonstrated.\n\nTrigger: after login completes (full feature phase), an initiator that has\ndeclared a large TargetRecvDataSegmentLength and a FirstBurstLength that\npermits unsolicited/immediate data sends a PDU whose declared data-segment\nlength exceeds what was received. With KASAN:\n\n  BUG: KASAN: slab-out-of-bounds in sg_copy_buffer+0x150/0x1c0\n  Read of size 4096 at addr ffff888109720800 by task kworker/1:0H/25\n  Workqueue: ib-comp-wq ib_cq_poll_work\n  Call Trace:\n   sg_copy_buffer+0x150/0x1c0\n   isert_recv_done+0xba6/0x2390\n   __ib_process_cq+0xe1/0x390\n   ib_cq_poll_work+0x46/0x150\n\nisert_recv_done+0xba6 resolves to isert_handle_iscsi_dataout()\n(ib_isert.c:1160), inlined through isert_rx_opcode().\n\nValidate wc->byte_len against the framing in isert_recv_done() before the\nPDU reaches any handler, and reinstate the connection if it is short.\nBecause the test compares without subtracting the header length, it also\nrejects PDUs shorter than the iSER and iSCSI headers, which would otherwise\nbe parsed out of stale descriptor contents. The login handler rejects PDUs\nshorter than ISER_HEADERS_LEN (commit 29e7b925ae6d (\"IB/isert: Reject login\nPDUs shorter than ISER_HEADERS_LEN\")) but does not bound the declared\nlength either; that is fixed in the next patch. The data handlers had no\nlength check at all.\n\nisert reads the data segment from a fixed offset: isert_get_data()\nreturns the iSER header plus ISER_HEADERS_LEN and makes no adjustment for\nan AHS.  The bytes the handlers touch are therefore exactly\n[ISER_HEADERS_LEN, ISER_HEADERS_LEN + dlength), and comparing that sum\nagainst wc->byte_len bounds precisely the region that is read.  An AHS\nterm would only make the test stricter without bounding anything furth\n---truncated---","Type":"Description","Title":"IB/isert: reject PDUs declaring more data than was received"}]}}}