Impact
In the Linux kernel’s ISERT implementation, receive buffers are posted before session registration completes. If an initiator sends commands before the target sends the final Login Response, the kernel may attempt to execute a SCSI command against a session whose se_tpg is still NULL, leading to a null‑pointer dereference and an OOPS that crashes the kernel. This results in a denial‑of‑service crash for the affected system.
Affected Systems
All Linux kernel versions that contain the affected ISERT code are impacted until the patch that defers buffer posting is applied. The issue arises on any system that uses the IB or RoCE interface for iSER sessions, regardless of hardware, because the bug is in the kernel’s session handling logic.
Risk and Exploitability
The CVSS score of 7.5 classifies the vulnerability as high severity, but the EPSS score of < 1 % indicates a very low likelihood of exploitation. The vulnerability was not listed in the CISA KEV catalog. An attacker would need the ability to send iSER or RoCE traffic to the target and would have to issue commands before the target acknowledges the final Login Response. Although the attack vector is technically remote over IB/RoCE, the low event probability and absence of publicly known exploits reduce the current risk to a moderate level. Organizations should treat the crash as a critical outage risk and patch promptly.
OpenCVE Enrichment
Debian DLA
Debian DSA