{"api_version":"1","generated_at":"2026-10-07T02:35:34+00:00","cve":"CVE-2026-98358","urls":{"html":"https://cve.report/CVE-2026-98358","api":"https://cve.report/api/cve/CVE-2026-98358.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-98358","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-98358"},"summary":{"title":"IB/iser: reject a remote invalidation of an unregistered direction","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nIB/iser: reject a remote invalidation of an unregistered direction\n\nA write command whose data is sent entirely as immediate data is not\nregistered.  iser_reg_mem_fastreg() takes the DMA key path and leaves\nrdma_reg[ISER_DIR_OUT].desc at NULL, while iser_dma_map_task_data() has\nalready set dir[ISER_DIR_OUT].\n\niser_check_remote_inv() looks at dir[] alone and hands the descriptor to\niser_inv_desc(), which reads desc->sig_protected.  A target that answers\nsuch a command with IB_WR_SEND_WITH_INV faults the initiator.\nLeaving those commands unregistered is deliberate.\n\nThe same function already terminates the connection when a target sends\na remote invalidation the initiator did not ask for.  A target that\ninvalidates a direction that was never registered is in the same class,\nso give it the same answer.\n\n  Oops: general protection fault, probably for non-canonical address 0xdffffc0000000004: 0000 [#1] SMP KASAN NOPTI\n  KASAN: null-ptr-deref in range [0x0000000000000020-0x0000000000000027]\n  CPU: 0 UID: 0 PID: 40 Comm: kworker/u8:2 Not tainted 7.2.0-rc5-ISERHOST-gf5098b6bae76-dirty #3 PREEMPT(lazy)\n  Hardware name: QEMU Ubuntu 24.04 PC v2 (i440FX + PIIX, arch_caps fix, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014\n  Workqueue: rxe_wq do_work\n  RIP: 0010:iser_task_rsp+0x6d6/0xec0\n  Code: 48 c1 ea 03 80 3c 02 00 0f 85 ba 06 00 00 48 8b 9b 78 01 00 00 48 b8 00 00 00 00 00 fc ff df 48 8d 7b 20 48 89 fa 48 c1 ea 03 <0f> b6 04 02 84 c0 74 06 0f 8e 76 06 00 00 80 7b 20 00 0f 84 3d 04\n  RSP: 0018:ffff88811b008db8 EFLAGS: 00010202\n  RAX: dffffc0000000000 RBX: 0000000000000000 RCX: 0000000000001848\n  RDX: 0000000000000004 RSI: 1ffff11021587b12 RDI: 0000000000000020\n  RBP: ffff88810adc1ae4 R08: ffff888109b7f860 R09: ffffffff90a922c0\n  R10: ffff88810adc1a1c R11: 000000000000003c R12: ffff888109b7f800\n  R13: ffff88810adc1acc R14: ffff888109b7f820 R15: 0000000000000000\n  FS:  0000000000000000(0000) GS:ffff88818a676000(0000) knlGS:0000000000000000\n  CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n  CR2: 00000000005afe2b CR3: 000000010af23005 CR4: 0000000000770ef0\n  PKRU: 55555554\n  Call Trace:\n   <IRQ>\n   __ib_process_cq+0xe1/0x390\n   ib_poll_handler+0x6e/0x200\n   irq_poll_softirq+0x1df/0x480\n   ? clockevents_program_event+0x2ba/0x860\n   ? __pfx_irq_poll_softirq+0x10/0x10\n   handle_softirqs+0x18e/0x590\n   ? __pfx_handle_softirqs+0x10/0x10\n   ? __hrtimer_rearm_deferred+0x156/0x450\n   do_softirq+0x3b/0x60\n   </IRQ>\n   <TASK>\n   __local_bh_enable_ip+0x61/0x70\n   __alloc_skb+0x732/0x890\n   ? _raw_spin_lock_irqsave+0x85/0xe0\n   ? __pfx___alloc_skb+0x10/0x10\n   ? _raw_read_unlock_irqrestore+0x16/0x50\n   rxe_init_packet+0x16b/0x4f0\n   prepare_ack_packet+0xb8/0x830\n   rxe_receiver+0x499/0x9980\n   ? __pfx_rxe_receiver+0x10/0x10\n   ? rxe_completer+0x29e5/0x38c0\n   ? hrtimer_start_range_ns_common+0x75f/0x1730\n   ? hrtimer_start_range_ns+0xa6/0x2c0\n   ? __pfx__raw_spin_lock_irqsave+0x10/0x10\n   ? __pfx_rxe_receiver+0x10/0x10\n   do_work+0x144/0x470\n   process_one_work+0x633/0x1030\n   ? assign_work+0x11d/0x370\n   worker_thread+0x45b/0xd10\n   ? __pfx_worker_thread+0x10/0x10\n   kthread+0x2c6/0x3b0\n   ? recalc_sigpending+0x15c/0x1e0\n   ? __pfx_kthread+0x10/0x10\n   ret_from_fork+0x36e/0x5a0\n   ? __pfx_ret_from_fork+0x10/0x10\n   ? __switch_to+0x572/0xdd0\n   ? __pfx_kthread+0x10/0x10\n   ret_from_fork_asm+0x1a/0x30\n   </TASK>\n  Modules linked in:\n  ---[ end trace 0000000000000000 ]---","state":"PUBLISHED","assigner":"Linux","published_at":"2026-10-06 09:18:29","updated_at":"2026-10-06 09:18:29"},"problem_types":[],"metrics":[],"references":[{"url":"https://git.kernel.org/stable/c/19ddd4af7fce9200e70882f622011e9dd130f427","name":"https://git.kernel.org/stable/c/19ddd4af7fce9200e70882f622011e9dd130f427","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/b9e37452915feaa8422af87dea5d0c16a7d1ff13","name":"https://git.kernel.org/stable/c/b9e37452915feaa8422af87dea5d0c16a7d1ff13","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/d85f0f0a7c85756fc992c70d869706f19dac9259","name":"https://git.kernel.org/stable/c/d85f0f0a7c85756fc992c70d869706f19dac9259","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/ceecf3f9c322fc6937a66682942a26ad13a34a07","name":"https://git.kernel.org/stable/c/ceecf3f9c322fc6937a66682942a26ad13a34a07","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/198e4db9add54a50cce60a5d80b8f0ee5456b65a","name":"https://git.kernel.org/stable/c/198e4db9add54a50cce60a5d80b8f0ee5456b65a","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/b4d278c91209931199db9c0836dc2e21a7593dad","name":"https://git.kernel.org/stable/c/b4d278c91209931199db9c0836dc2e21a7593dad","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/6ed3ebaff3345837f0528d85bd39ce573c7b9a41","name":"https://git.kernel.org/stable/c/6ed3ebaff3345837f0528d85bd39ce573c7b9a41","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/9d145a2d8d6f8f2cc460b80df41870819048f2a0","name":"https://git.kernel.org/stable/c/9d145a2d8d6f8f2cc460b80df41870819048f2a0","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-98358","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-98358","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 59caaed7a72a0e3750dfb84636dae6b781559310 198e4db9add54a50cce60a5d80b8f0ee5456b65a git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 59caaed7a72a0e3750dfb84636dae6b781559310 b9e37452915feaa8422af87dea5d0c16a7d1ff13 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 59caaed7a72a0e3750dfb84636dae6b781559310 19ddd4af7fce9200e70882f622011e9dd130f427 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 59caaed7a72a0e3750dfb84636dae6b781559310 9d145a2d8d6f8f2cc460b80df41870819048f2a0 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 59caaed7a72a0e3750dfb84636dae6b781559310 b4d278c91209931199db9c0836dc2e21a7593dad git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 59caaed7a72a0e3750dfb84636dae6b781559310 6ed3ebaff3345837f0528d85bd39ce573c7b9a41 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 59caaed7a72a0e3750dfb84636dae6b781559310 ceecf3f9c322fc6937a66682942a26ad13a34a07 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 59caaed7a72a0e3750dfb84636dae6b781559310 d85f0f0a7c85756fc992c70d869706f19dac9259 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 4.5","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 4.5 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 5.10.271 5.10.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 5.15.222 5.15.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.1.189 6.1.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.6.158 6.6.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.12.112 6.12.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.54 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2.8 7.2.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.3-rc4 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"98358","cve":"CVE-2026-98358","epss":"0.001640000","percentile":"0.051110000","score_date":"2026-10-06","updated_at":"2026-10-07 00:14:55"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["drivers/infiniband/ulp/iser/iser_initiator.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"198e4db9add54a50cce60a5d80b8f0ee5456b65a","status":"affected","version":"59caaed7a72a0e3750dfb84636dae6b781559310","versionType":"git"},{"lessThan":"b9e37452915feaa8422af87dea5d0c16a7d1ff13","status":"affected","version":"59caaed7a72a0e3750dfb84636dae6b781559310","versionType":"git"},{"lessThan":"19ddd4af7fce9200e70882f622011e9dd130f427","status":"affected","version":"59caaed7a72a0e3750dfb84636dae6b781559310","versionType":"git"},{"lessThan":"9d145a2d8d6f8f2cc460b80df41870819048f2a0","status":"affected","version":"59caaed7a72a0e3750dfb84636dae6b781559310","versionType":"git"},{"lessThan":"b4d278c91209931199db9c0836dc2e21a7593dad","status":"affected","version":"59caaed7a72a0e3750dfb84636dae6b781559310","versionType":"git"},{"lessThan":"6ed3ebaff3345837f0528d85bd39ce573c7b9a41","status":"affected","version":"59caaed7a72a0e3750dfb84636dae6b781559310","versionType":"git"},{"lessThan":"ceecf3f9c322fc6937a66682942a26ad13a34a07","status":"affected","version":"59caaed7a72a0e3750dfb84636dae6b781559310","versionType":"git"},{"lessThan":"d85f0f0a7c85756fc992c70d869706f19dac9259","status":"affected","version":"59caaed7a72a0e3750dfb84636dae6b781559310","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["drivers/infiniband/ulp/iser/iser_initiator.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"4.5"},{"lessThan":"4.5","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"5.10.*","status":"unaffected","version":"5.10.271","versionType":"semver"},{"lessThanOrEqual":"5.15.*","status":"unaffected","version":"5.15.222","versionType":"semver"},{"lessThanOrEqual":"6.1.*","status":"unaffected","version":"6.1.189","versionType":"semver"},{"lessThanOrEqual":"6.6.*","status":"unaffected","version":"6.6.158","versionType":"semver"},{"lessThanOrEqual":"6.12.*","status":"unaffected","version":"6.12.112","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.54","versionType":"semver"},{"lessThanOrEqual":"7.2.*","status":"unaffected","version":"7.2.8","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.3-rc4","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"5.10.271","versionStartIncluding":"4.5","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"5.15.222","versionStartIncluding":"4.5","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.1.189","versionStartIncluding":"4.5","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.6.158","versionStartIncluding":"4.5","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.12.112","versionStartIncluding":"4.5","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.54","versionStartIncluding":"4.5","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2.8","versionStartIncluding":"4.5","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.3-rc4","versionStartIncluding":"4.5","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nIB/iser: reject a remote invalidation of an unregistered direction\n\nA write command whose data is sent entirely as immediate data is not\nregistered.  iser_reg_mem_fastreg() takes the DMA key path and leaves\nrdma_reg[ISER_DIR_OUT].desc at NULL, while iser_dma_map_task_data() has\nalready set dir[ISER_DIR_OUT].\n\niser_check_remote_inv() looks at dir[] alone and hands the descriptor to\niser_inv_desc(), which reads desc->sig_protected.  A target that answers\nsuch a command with IB_WR_SEND_WITH_INV faults the initiator.\nLeaving those commands unregistered is deliberate.\n\nThe same function already terminates the connection when a target sends\na remote invalidation the initiator did not ask for.  A target that\ninvalidates a direction that was never registered is in the same class,\nso give it the same answer.\n\n  Oops: general protection fault, probably for non-canonical address 0xdffffc0000000004: 0000 [#1] SMP KASAN NOPTI\n  KASAN: null-ptr-deref in range [0x0000000000000020-0x0000000000000027]\n  CPU: 0 UID: 0 PID: 40 Comm: kworker/u8:2 Not tainted 7.2.0-rc5-ISERHOST-gf5098b6bae76-dirty #3 PREEMPT(lazy)\n  Hardware name: QEMU Ubuntu 24.04 PC v2 (i440FX + PIIX, arch_caps fix, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014\n  Workqueue: rxe_wq do_work\n  RIP: 0010:iser_task_rsp+0x6d6/0xec0\n  Code: 48 c1 ea 03 80 3c 02 00 0f 85 ba 06 00 00 48 8b 9b 78 01 00 00 48 b8 00 00 00 00 00 fc ff df 48 8d 7b 20 48 89 fa 48 c1 ea 03 <0f> b6 04 02 84 c0 74 06 0f 8e 76 06 00 00 80 7b 20 00 0f 84 3d 04\n  RSP: 0018:ffff88811b008db8 EFLAGS: 00010202\n  RAX: dffffc0000000000 RBX: 0000000000000000 RCX: 0000000000001848\n  RDX: 0000000000000004 RSI: 1ffff11021587b12 RDI: 0000000000000020\n  RBP: ffff88810adc1ae4 R08: ffff888109b7f860 R09: ffffffff90a922c0\n  R10: ffff88810adc1a1c R11: 000000000000003c R12: ffff888109b7f800\n  R13: ffff88810adc1acc R14: ffff888109b7f820 R15: 0000000000000000\n  FS:  0000000000000000(0000) GS:ffff88818a676000(0000) knlGS:0000000000000000\n  CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n  CR2: 00000000005afe2b CR3: 000000010af23005 CR4: 0000000000770ef0\n  PKRU: 55555554\n  Call Trace:\n   <IRQ>\n   __ib_process_cq+0xe1/0x390\n   ib_poll_handler+0x6e/0x200\n   irq_poll_softirq+0x1df/0x480\n   ? clockevents_program_event+0x2ba/0x860\n   ? __pfx_irq_poll_softirq+0x10/0x10\n   handle_softirqs+0x18e/0x590\n   ? __pfx_handle_softirqs+0x10/0x10\n   ? __hrtimer_rearm_deferred+0x156/0x450\n   do_softirq+0x3b/0x60\n   </IRQ>\n   <TASK>\n   __local_bh_enable_ip+0x61/0x70\n   __alloc_skb+0x732/0x890\n   ? _raw_spin_lock_irqsave+0x85/0xe0\n   ? __pfx___alloc_skb+0x10/0x10\n   ? _raw_read_unlock_irqrestore+0x16/0x50\n   rxe_init_packet+0x16b/0x4f0\n   prepare_ack_packet+0xb8/0x830\n   rxe_receiver+0x499/0x9980\n   ? __pfx_rxe_receiver+0x10/0x10\n   ? rxe_completer+0x29e5/0x38c0\n   ? hrtimer_start_range_ns_common+0x75f/0x1730\n   ? hrtimer_start_range_ns+0xa6/0x2c0\n   ? __pfx__raw_spin_lock_irqsave+0x10/0x10\n   ? __pfx_rxe_receiver+0x10/0x10\n   do_work+0x144/0x470\n   process_one_work+0x633/0x1030\n   ? assign_work+0x11d/0x370\n   worker_thread+0x45b/0xd10\n   ? __pfx_worker_thread+0x10/0x10\n   kthread+0x2c6/0x3b0\n   ? recalc_sigpending+0x15c/0x1e0\n   ? __pfx_kthread+0x10/0x10\n   ret_from_fork+0x36e/0x5a0\n   ? __pfx_ret_from_fork+0x10/0x10\n   ? __switch_to+0x572/0xdd0\n   ? __pfx_kthread+0x10/0x10\n   ret_from_fork_asm+0x1a/0x30\n   </TASK>\n  Modules linked in:\n  ---[ end trace 0000000000000000 ]---"}],"providerMetadata":{"dateUpdated":"2026-10-06T08:46:45.128Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/198e4db9add54a50cce60a5d80b8f0ee5456b65a"},{"url":"https://git.kernel.org/stable/c/b9e37452915feaa8422af87dea5d0c16a7d1ff13"},{"url":"https://git.kernel.org/stable/c/19ddd4af7fce9200e70882f622011e9dd130f427"},{"url":"https://git.kernel.org/stable/c/9d145a2d8d6f8f2cc460b80df41870819048f2a0"},{"url":"https://git.kernel.org/stable/c/b4d278c91209931199db9c0836dc2e21a7593dad"},{"url":"https://git.kernel.org/stable/c/6ed3ebaff3345837f0528d85bd39ce573c7b9a41"},{"url":"https://git.kernel.org/stable/c/ceecf3f9c322fc6937a66682942a26ad13a34a07"},{"url":"https://git.kernel.org/stable/c/d85f0f0a7c85756fc992c70d869706f19dac9259"}],"title":"IB/iser: reject a remote invalidation of an unregistered direction","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-98358","datePublished":"2026-10-06T08:46:45.128Z","dateReserved":"2026-09-25T10:25:14.344Z","dateUpdated":"2026-10-06T08:46:45.128Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-10-06 09:18:29","lastModifiedDate":"2026-10-06 09:18:29","problem_types":[],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"98358","Ordinal":"1","Title":"IB/iser: reject a remote invalidation of an unregistered directi","CVE":"CVE-2026-98358","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"98358","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nIB/iser: reject a remote invalidation of an unregistered direction\n\nA write command whose data is sent entirely as immediate data is not\nregistered.  iser_reg_mem_fastreg() takes the DMA key path and leaves\nrdma_reg[ISER_DIR_OUT].desc at NULL, while iser_dma_map_task_data() has\nalready set dir[ISER_DIR_OUT].\n\niser_check_remote_inv() looks at dir[] alone and hands the descriptor to\niser_inv_desc(), which reads desc->sig_protected.  A target that answers\nsuch a command with IB_WR_SEND_WITH_INV faults the initiator.\nLeaving those commands unregistered is deliberate.\n\nThe same function already terminates the connection when a target sends\na remote invalidation the initiator did not ask for.  A target that\ninvalidates a direction that was never registered is in the same class,\nso give it the same answer.\n\n  Oops: general protection fault, probably for non-canonical address 0xdffffc0000000004: 0000 [#1] SMP KASAN NOPTI\n  KASAN: null-ptr-deref in range [0x0000000000000020-0x0000000000000027]\n  CPU: 0 UID: 0 PID: 40 Comm: kworker/u8:2 Not tainted 7.2.0-rc5-ISERHOST-gf5098b6bae76-dirty #3 PREEMPT(lazy)\n  Hardware name: QEMU Ubuntu 24.04 PC v2 (i440FX + PIIX, arch_caps fix, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014\n  Workqueue: rxe_wq do_work\n  RIP: 0010:iser_task_rsp+0x6d6/0xec0\n  Code: 48 c1 ea 03 80 3c 02 00 0f 85 ba 06 00 00 48 8b 9b 78 01 00 00 48 b8 00 00 00 00 00 fc ff df 48 8d 7b 20 48 89 fa 48 c1 ea 03 <0f> b6 04 02 84 c0 74 06 0f 8e 76 06 00 00 80 7b 20 00 0f 84 3d 04\n  RSP: 0018:ffff88811b008db8 EFLAGS: 00010202\n  RAX: dffffc0000000000 RBX: 0000000000000000 RCX: 0000000000001848\n  RDX: 0000000000000004 RSI: 1ffff11021587b12 RDI: 0000000000000020\n  RBP: ffff88810adc1ae4 R08: ffff888109b7f860 R09: ffffffff90a922c0\n  R10: ffff88810adc1a1c R11: 000000000000003c R12: ffff888109b7f800\n  R13: ffff88810adc1acc R14: ffff888109b7f820 R15: 0000000000000000\n  FS:  0000000000000000(0000) GS:ffff88818a676000(0000) knlGS:0000000000000000\n  CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n  CR2: 00000000005afe2b CR3: 000000010af23005 CR4: 0000000000770ef0\n  PKRU: 55555554\n  Call Trace:\n   <IRQ>\n   __ib_process_cq+0xe1/0x390\n   ib_poll_handler+0x6e/0x200\n   irq_poll_softirq+0x1df/0x480\n   ? clockevents_program_event+0x2ba/0x860\n   ? __pfx_irq_poll_softirq+0x10/0x10\n   handle_softirqs+0x18e/0x590\n   ? __pfx_handle_softirqs+0x10/0x10\n   ? __hrtimer_rearm_deferred+0x156/0x450\n   do_softirq+0x3b/0x60\n   </IRQ>\n   <TASK>\n   __local_bh_enable_ip+0x61/0x70\n   __alloc_skb+0x732/0x890\n   ? _raw_spin_lock_irqsave+0x85/0xe0\n   ? __pfx___alloc_skb+0x10/0x10\n   ? _raw_read_unlock_irqrestore+0x16/0x50\n   rxe_init_packet+0x16b/0x4f0\n   prepare_ack_packet+0xb8/0x830\n   rxe_receiver+0x499/0x9980\n   ? __pfx_rxe_receiver+0x10/0x10\n   ? rxe_completer+0x29e5/0x38c0\n   ? hrtimer_start_range_ns_common+0x75f/0x1730\n   ? hrtimer_start_range_ns+0xa6/0x2c0\n   ? __pfx__raw_spin_lock_irqsave+0x10/0x10\n   ? __pfx_rxe_receiver+0x10/0x10\n   do_work+0x144/0x470\n   process_one_work+0x633/0x1030\n   ? assign_work+0x11d/0x370\n   worker_thread+0x45b/0xd10\n   ? __pfx_worker_thread+0x10/0x10\n   kthread+0x2c6/0x3b0\n   ? recalc_sigpending+0x15c/0x1e0\n   ? __pfx_kthread+0x10/0x10\n   ret_from_fork+0x36e/0x5a0\n   ? __pfx_ret_from_fork+0x10/0x10\n   ? __switch_to+0x572/0xdd0\n   ? __pfx_kthread+0x10/0x10\n   ret_from_fork_asm+0x1a/0x30\n   </TASK>\n  Modules linked in:\n  ---[ end trace 0000000000000000 ]---","Type":"Description","Title":"IB/iser: reject a remote invalidation of an unregistered directi"}]}}}