{"id":"CVE-2026-90413","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nIB/isert: reject login PDUs declaring more data than was received\n\nisert_login_recv_done() records how many bytes the HCA actually placed in\nthe login buffer, but nothi…","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nIB/isert: reject login PDUs declaring more data than was received\n\nisert_login_recv_done() records how many bytes the HCA actually placed in\nthe login buffer, but nothi…","severity":"critical","cvss":9.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","vendor":"Linux","product":"Linux","affected":["Linux >= b8d26b3be8b33682cf163274ed07479a70554633 < b1f3313e7b3e396e4985fea5c709477387e0a065","Linux >= b8d26b3be8b33682cf163274ed07479a70554633 < 228aaa620fe6a7bc8b5b21dd348b4836b1760c61","Linux >= b8d26b3be8b33682cf163274ed07479a70554633 < 0d9c0586af703890afe1bd0cfe641e3a3af1c32d","Linux >= b8d26b3be8b33682cf163274ed07479a70554633 < 44fe800ec13386c88bd5b32bcd1deaa1e17535d5","Linux >= b8d26b3be8b33682cf163274ed07479a70554633 < 71ec8bbfa4a183f1e623662f9cfbcd702e433bdb","Linux >= b8d26b3be8b33682cf163274ed07479a70554633 < c345d9d0b3eefc990bb90cf565325785aab06aab","Linux >= b8d26b3be8b33682cf163274ed07479a70554633 < 48812c8103071d550d9ab4a3431be5bdc52255bc","Linux >= b8d26b3be8b33682cf163274ed07479a70554633 < 2488b5b4827e5415768afc8daf097e8eb83c98df","Linux 3.10"],"published":"2026-09-17","updated":"2026-09-18","sourceUpdated":"2026-09-18T18:17:58.063","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-90413","references":[{"url":"https://git.kernel.org/stable/c/0d9c0586af703890afe1bd0cfe641e3a3af1c32d","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/228aaa620fe6a7bc8b5b21dd348b4836b1760c61","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2488b5b4827e5415768afc8daf097e8eb83c98df","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/44fe800ec13386c88bd5b32bcd1deaa1e17535d5","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/48812c8103071d550d9ab4a3431be5bdc52255bc","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/71ec8bbfa4a183f1e623662f9cfbcd702e433bdb","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b1f3313e7b3e396e4985fea5c709477387e0a065","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c345d9d0b3eefc990bb90cf565325785aab06aab","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"epss":0.00829,"epssPercentile":0.55981,"ingestedAt":"2026-09-17T16:21:47.796Z","slug":"CVE-2026-90413","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nIB/isert: reject login PDUs declaring more data than was received\n\nisert_login_recv_done() records how many bytes the HCA actually placed in\nthe login buffer, but nothing compares that against the length the login\nPDU's BHS declares.  isert_rx_login_req() copies min(login_req_len,\nMAX_KEY_VALUE_PAIRS) bytes into login->req_buf, and the login code then\nreads the declared length back out of that buffer - for the first PDU in\niscsi_target_locate_portal(),\n\n\tpayload_length = ntoh24(login_req->dlength);\n\ttmpbuf = kmemdup_nul(login->req_buf, payload_length, GFP_KERNEL);\n\nand for the ones after it in iscsi_decode_text_input(), reached from\niscsi_target_do_login().\n\nlogin->req_buf is a fixed MAX_KEY_VALUE_PAIRS (8192) byte allocation, so\nan initiator that declares more than it sends reads off the end of it,\nbefore authentication and with the length under its control:\n\n  BUG: KASAN: slab-out-of-bounds in kmemdup_nul+0x43/0x80\n  Read of size 8193 at addr ffff8881056a8000 by task iscsi_np/167\n   __asan_memcpy+0x23/0x60\n   kmemdup_nul+0x43/0x80\n   iscsi_target_locate_portal+0x48d/0x1180\n   iscsi_target_login_thread+0x19a9/0x3350\n  Allocated by task 167:\n   __kmalloc_cache_noprof+0x158/0x370\n   iscsi_target_login_thread+0x971/0x3350\n  which belongs to the cache kmalloc-8k of size 8192\n  allocated 8192-byte region\n\nFalsifying the second login PDU instead reaches the other reader, on the\nsame buffer:\n\n  BUG: KASAN: slab-out-of-bounds in kmemdup_nul+0x43/0x80\n  Read of size 8193 at addr ffff888104d10000 by task kworker/1:1/50\n  Workqueue: isert_login_wq iscsi_target_do_login_rx\n   __asan_memcpy+0x23/0x60\n   kmemdup_nul+0x43/0x80\n   iscsi_decode_text_input+0xc6/0x11c0\n   iscsi_target_do_login+0x261/0x1470\n   iscsi_target_do_login_rx+0x51d/0x7d0\n\niscsit over TCP is not exposed: iscsit_get_login_rx() validates the\ndeclared length with iscsi_target_check_login_request() and then reads\nexactly that many bytes off the socket, so the declared length governs\nhow much arrives rather than how much is copied out of an already-filled\nbuffer.  isert does not call iscsi_target_check_login_request() at all.\n\nReject a login PDU whose declared DataSegmentLength exceeds what was\nreceived, in both paths that reach isert_rx_login_req():\nisert_get_login_rx() for the first login PDU and isert_login_recv_done()\nfor the ones after it.  dlength <= login_req_len is allowed because the\nreceived count can include up to three bytes of iSCSI padding.\n\nOnce the check is in place the copy out can no longer exceed the copy in:\nthe posted login SGE is ISER_RX_PAYLOAD_SIZE, so login_req_len cannot\nexceed MAX_KEY_VALUE_PAIRS and the min() in isert_rx_login_req() is\nlogin_req_len.\n\nLike the existing short-PDU check added by 29e7b925ae6d, the reject in\nisert_login_recv_done() returns without completing login_req_comp, so a\nmalformed subsequent PDU leaves the login to be torn down by the login\ntimer rather than failing immediately.  The first-PDU path returns an\nerror and fails straight away.\n\nReproduced on 7.2.0-rc4 with soft-RoCE (rdma_rxe) under KASAN, using an\ninitiator that sends the real key=value payload while declaring 8193 in\nthe BHS, on the first login PDU and on the second in separate runs.  The\nreported read size tracks the declared value exactly; 16384 and 61440\nbehave the same.  Unpatched 3 of 3 runs report on each of the two paths,\npatched 0 of 3 on both, run alternately in a single session, and a normal\nlogin still completes on the patched build.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":50,"depthScoreParts":{"impact":50.1,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[{"seq":207311,"id":"CVE-2026-90413","ts":1789757340694,"field":"cvss","old":null,"new":"9.1"},{"seq":207310,"id":"CVE-2026-90413","ts":1789757340694,"field":"severity","old":"none","new":"critical"}]}