Description
In the Linux kernel, the following vulnerability has been resolved:

IB/isert: post the full-feature receive buffers after session registration

isert_put_login_tx() posts the full-feature receive buffers before
__transport_register_session() runs, so an initiator that does not wait
for the final Login Response can still have a SCSI command executed
against an se_session whose se_tpg is NULL - the same oops as the
previous patch, at target_submit+0xbe.

Post them from isert_get_rx_pdu(), which the previous patch already uses
to send that response, and post them before that send: the receive queue
is filled at the moment the initiator is told it may use it. Allocating
there keeps the existing property that a memory allocation failure cannot
happen once the final Login Response is on the wire.

The receive queue is already empty between the final Login Request and
isert_post_recvm(); this moves the second point later, from a median of
92 us to 172 us over 1200 logins. Only an initiator that sends before it
has been told to can reach that window, and on IB and RoCE its send is
retried there until the buffers appear - isert_rdma_accept() asks for
rnr_retry_count = 7. iWARP has no RNR flow control, so there the same
send terminates the connection instead.

Measured over rxe, 400 login cycles per run, with an initiator that does
not wait: an instrumented build counted no entries to isert_recv_done()
before the buffers are posted in 10 runs, where that initiator oopsed
8 of 10 unpatched runs and 5 of 10 with only the previous patch.

Not tested: iWARP, discovery sessions over iSER, and real HCAs.
Published: 2026-09-17
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Kernel Crash (Null Pointer Dereference)
Action: Patch Immediately
AI Analysis

Impact

In the Linux kernel’s ISERT implementation, receive buffers are posted before session registration completes. If an initiator sends commands before the target sends the final Login Response, the kernel may attempt to execute a SCSI command against a session whose se_tpg is still NULL, leading to a null‑pointer dereference and an OOPS that crashes the kernel. This results in a denial‑of‑service crash for the affected system.

Affected Systems

All Linux kernel versions that contain the affected ISERT code are impacted until the patch that defers buffer posting is applied. The issue arises on any system that uses the IB or RoCE interface for iSER sessions, regardless of hardware, because the bug is in the kernel’s session handling logic.

Risk and Exploitability

The CVSS score of 7.5 classifies the vulnerability as high severity, but the EPSS score of < 1 % indicates a very low likelihood of exploitation. The vulnerability was not listed in the CISA KEV catalog. An attacker would need the ability to send iSER or RoCE traffic to the target and would have to issue commands before the target acknowledges the final Login Response. Although the attack vector is technically remote over IB/RoCE, the low event probability and absence of publicly known exploits reduce the current risk to a moderate level. Organizations should treat the crash as a critical outage risk and patch promptly.

Generated by OpenCVE AI on September 20, 2026 at 00:57 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the kernel patch that moves receive buffer posting to after session registration (the commit referenced in the advisory).
  • Replace or upgrade the kernel to a version that includes this fix if the patch is not yet available for your distribution.
  • If immediate kernel remediation is not possible, disable the ISERT/IB or RoCE interfaces for the affected sessions as a temporary measure to prevent the crash.

Generated by OpenCVE AI on September 20, 2026 at 00:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 20 Sep 2026 01:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: IB/isert: post the full-feature receive buffers after session registration isert_put_login_tx() posts the full-feature receive buffers before __transport_register_session() runs, so an initiator that does not wait for the final Login Response can still have a SCSI command executed against an se_session whose se_tpg is NULL - the same oops as the previous patch, at target_submit+0xbe. Post them from isert_get_rx_pdu(), which the previous patch already uses to send that response, and post them before that send: the receive queue is filled at the moment the initiator is told it may use it. Allocating there keeps the existing property that a memory allocation failure cannot happen once the final Login Response is on the wire. The receive queue is already empty between the final Login Request and isert_post_recvm(); this moves the second point later, from a median of 92 us to 172 us over 1200 logins. Only an initiator that sends before it has been told to can reach that window, and on IB and RoCE its send is retried there until the buffers appear - isert_rdma_accept() asks for rnr_retry_count = 7. iWARP has no RNR flow control, so there the same send terminates the connection instead. Measured over rxe, 400 login cycles per run, with an initiator that does not wait: an instrumented build counted no entries to isert_recv_done() before the buffers are posted in 10 runs, where that initiator oopsed 8 of 10 unpatched runs and 5 of 10 with only the previous patch. Not tested: iWARP, discovery sessions over iSER, and real HCAs.
Title IB/isert: post the full-feature receive buffers after session registration
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:54:23.208Z

Reserved: 2026-09-11T19:38:34.798Z

Link: CVE-2026-90293

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:26.543

Modified: 2026-09-18T18:17:52.310

Link: CVE-2026-90293

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T01:00:13Z

Weaknesses