Impact
The defect in iSCSI target handling removes the expected null terminator from a login payload buffer. When a login request’s DataSegmentLength, after padding, fills the entire 8192‑byte buffer, no byte remains to terminate the string. Subsequent kernel paths that treat this payload as a C string read beyond the buffer boundary, enabling an attacker to exfiltrate arbitrary kernel memory or potentially leverage the leak to execute code. The flaw is triggered by an unauthenticated initiator against a portal configured for CHAP authentication – the CHAP path is exercised even when no authentication is required because the system accepts the initiator’s login request and later performs the vulnerable string handling.
Affected Systems
All Linux kernel versions released before the commit that reserves an extra terminator byte for the iSCSI login payload are affected. The issue resides in the SCSI target subsystem, specifically the iscsi_target_check_login_request and iscsi_get_login_rx functions within the kernel’s iSCSI target driver.
Risk and Exploitability
The CVSS score of 9.1 reflects the high severity of the bug, while the EPSS score of < 1% indicates a low but non‑zero chance of exploitation. The flaw is not yet listed in the CISA KEV catalog. An attacker with network access to an iSCSI target can craft a login PDU to trigger the overflow. The exploit requires no special privileges on the target and can result in kernel memory disclosure or a foothold for privilege escalation.
OpenCVE Enrichment
Debian DLA
Debian DSA