Impact
A null‑pointer dereference in the iSER target (isert) path is triggered when an initiator sends a SCSI command immediately after receiving a Login Response that is delivered before the session is fully registered. The kernel dereferences a NULL session pointer, causing a general protection fault and an oops that can lead to a kernel panic, thereby disrupting system availability.
Affected Systems
All Linux kernel releases that ship the isert (iSER) target module, which includes the default kernels of major distributions such as Ubuntu, Debian, Red Hat, and others. The vulnerability applies to any configuration where iSER is enabled; versions prior to the patch commit that delays the final Login Response are affected. Specific kernel versions are not listed, but the issue was demonstrated on a 7.2.x release.
Risk and Exploitability
The flaw is scored CVSS 7.5, indicating high severity. The EPSS score is under 1 %, reflecting a low likelihood of widespread exploitation at present. It is not listed in CISA’s KEV catalog. An attacker would need to act as an iSER initiator, establish a session, and issue SCSI commands as soon as the Login Response arrives. The attack is remote, does not provide execution privileges, but forces a kernel crash to deny service.
OpenCVE Enrichment
Debian DLA
Debian DSA