Impact
In the Linux kernel’s iSCSI over RDMA (iSER) implementation, the receive path does not verify that the byte length reported by the hardware matches the length declared in the PDU header. When an initiator advertises a data segment longer than what was actually received or larger than the fixed receive descriptor, the kernel copies that over‑declared length, causing an out‑of‑bounds read of the receive buffer. In the case where the declared length equals the buffer size and an immediate data path is used, the oversized scatterlist is passed to the back end so that data beyond the descriptor is written to the backing store. The unchecked lengths result in memory corruption that could be exploited by an adversary with control of an iSCSI initiator.
Affected Systems
The vulnerability exists in the Linux kernel’s iSCSI over RDMA (iSER) subsystem; any kernel version that has not yet incorporated the patch correcting this bounds‑check flaw is affected. No specific version numbers are listed, but any kernel implementing iSER without the bounds verification on received PDUs is vulnerable.
Risk and Exploitability
The CVSS score is 9.1, indicating high severity, while the EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote, through an iSCSI session after login, requiring an initiator that declares an oversized data segment. Because the flaw resides in the kernel’s receive path, exploitation could lead to arbitrary memory reads or writes from within kernel space, potentially enabling privilege escalation. No authentication is required beyond the normal iSCSI login process, making the vulnerability exploitable in many iSCSI deployments.
OpenCVE Enrichment
Debian DLA
Debian DSA