Impact
The isert iSCSI RDMA transport in the Linux kernel fails to compare the DataSegmentLength field of a login PDU against the actual number of bytes received. An attacker can craft a login request that declares a length larger than the payload, causing the kernel to read beyond the bounds of a fixed 8 KiB buffer. The resulting out‑of‑bounds read is reported by KASAN and can expose or potentially overwrite kernel memory, providing avenues for information disclosure or kernel privilege escalation. The underlying weakness is an omission of a bounds check on buffer length.
Affected Systems
This vulnerability affects any Linux kernel build that includes the unpatched isert iSCSI RDMA driver. While the defect was demonstrated on kernel 7.2.0‑rc4 with a soft‑RoCE implementation, any compiled kernel that contains the vulnerable isert code and handles iSCSI login requests over RDMA is susceptible. No vendor‑specific version list is published, and the fix is incorporated in later kernel releases through a commit that rejects PDUs with excessive declared length.
Risk and Exploitability
The CVSS score of 9.1 reflects the high severity of this flaw, and the EPSS score of less than 1% indicates a low current exploitation probability at the time of analysis. Nevertheless, the vulnerability is network‑reachable, can be triggered by an unauthenticated initiator, and requires no special privileges, making it a serious risk. The lack of a KEV listing means no publicly documented exploit exists yet, but the remote nature and the ability to read or write kernel memory make it a compelling target for attackers. An exploit would involve sending a malicious iSCSI login PDU over RDMA with a DataSegmentLength field that exceeds the actual data sent, inducing the out‑of‑bounds read.
OpenCVE Enrichment
Debian DLA
Debian DSA