---
id: CVE-2026-98357
title: >-
  In the Linux kernel, the following vulnerability has been resolved:


  IB/isert: wait for deferred control PDU completions before releasing the
  connection


  isert_send_done() hands ISTATE_SEND_TASKMGTRSP, ISTATE_SEND_REJECT and

  ISTATE_SEND_…
summary: >-
  In the Linux kernel, the following vulnerability has been resolved:


  IB/isert: wait for deferred control PDU completions before releasing the
  connection


  isert_send_done() hands ISTATE_SEND_TASKMGTRSP, ISTATE_SEND_REJECT and

  ISTATE_SEND_…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= b8d26b3be8b33682cf163274ed07479a70554633 <
    f5613acbe2e346d5c466ef0bd264fca936b69f82
  - >-
    Linux >= b8d26b3be8b33682cf163274ed07479a70554633 <
    ccdb1523f12bc8a9646de65055d1aafed9e9bcc6
  - >-
    Linux >= b8d26b3be8b33682cf163274ed07479a70554633 <
    0e230917670c6e6fe3243abfa11299fcbe05b1f4
  - >-
    Linux >= b8d26b3be8b33682cf163274ed07479a70554633 <
    505b242d9351690d1385bbe508ab4666f60363ce
  - >-
    Linux >= b8d26b3be8b33682cf163274ed07479a70554633 <
    7edb8a88d6c76237c8b4435765bee1009e26a50a
  - >-
    Linux >= b8d26b3be8b33682cf163274ed07479a70554633 <
    b96b8b3e41c308f606ffd10cfef1a7b9f97414cd
  - >-
    Linux >= b8d26b3be8b33682cf163274ed07479a70554633 <
    7908fbc597a694bbd99bfb59ece73bc3daded68e
  - >-
    Linux >= b8d26b3be8b33682cf163274ed07479a70554633 <
    a8fe3dfce8c0d8a76dc3d8486a5bff5feebe156f
  - Linux 3.10
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T09:18:29.293'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-98357'
references:
  - url: 'https://git.kernel.org/stable/c/0e230917670c6e6fe3243abfa11299fcbe05b1f4'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/505b242d9351690d1385bbe508ab4666f60363ce'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/7908fbc597a694bbd99bfb59ece73bc3daded68e'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/7edb8a88d6c76237c8b4435765bee1009e26a50a'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/a8fe3dfce8c0d8a76dc3d8486a5bff5feebe156f'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/b96b8b3e41c308f606ffd10cfef1a7b9f97414cd'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/ccdb1523f12bc8a9646de65055d1aafed9e9bcc6'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/f5613acbe2e346d5c466ef0bd264fca936b69f82'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-06T08:50:17.395Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

IB/isert: wait for deferred control PDU completions before releasing the connection

isert_send_done() hands ISTATE_SEND_TASKMGTRSP, ISTATE_SEND_REJECT and
ISTATE_SEND_TEXTRSP completions off to isert_comp_wq and returns.  The work
item then runs isert_completion_put() -> isert_put_cmd(), which reads
isert_conn->conn and takes conn->cmd_lock.

Nothing orders that work item against teardown.  isert_wait_conn() queues
isert_release_work, which frees isert_conn, and iscsit_close_connection()
frees the iscsit_conn right after it returns, so the queued work can run
against freed memory.

Count the deferred control PDU completions per connection and let
isert_wait_conn() wait for them before the release work is queued.

ISTATE_SEND_LOGOUTRSP is deliberately not counted: that branch runs
iscsit_logout_post_handler(), which ends up waiting for
conn->conn_wait_comp, and that completion is only sent by
iscsit_close_connection() after it has called iscsit_wait_conn().
Waiting for it here would deadlock.  Its wait stays the existing
isert_wait4logout().

The splat below is from a kernel with tracing printk()s and an msleep(200)
injected into isert_do_control_comp() to widen the window:

  BUG: KASAN: slab-use-after-free in isert_put_cmd+0x53d/0x620
  Read of size 8 at addr ffff8881054f1038 by task kworker/u17:1/182

  CPU: 0 UID: 0 PID: 182 Comm: kworker/u17:1 Tainted: G    B               7.2.0-rc5-TWIDE-gb8babf08acc7 #1 PREEMPT(lazy)
  Tainted: [B]=BAD_PAGE
  Hardware name: QEMU Ubuntu 24.04 PC v2 (i440FX + PIIX, arch_caps fix, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
  Workqueue: isert_comp_wq isert_do_control_comp
  Call Trace:
   <TASK>
   dump_stack_lvl+0x53/0x70
   print_report+0xd0/0x630
   ? __pfx__raw_spin_lock_irqsave+0x10/0x10
   ? _raw_spin_unlock_irqrestore+0x3e/0x70
   ? isert_put_cmd+0x53d/0x620
   kasan_report+0xce/0x100
   ? isert_put_cmd+0x53d/0x620
   isert_put_cmd+0x53d/0x620
   ? isert_completion_put+0x305/0x330
   ? isert_do_control_comp+0x2ef/0x310
   process_one_work+0x633/0x1030
   ? assign_work+0x11d/0x370
   worker_thread+0x45b/0xd10
   ? __pfx_worker_thread+0x10/0x10
   ? __pfx_worker_thread+0x10/0x10
   kthread+0x2c6/0x3b0
   ? recalc_sigpending+0x15c/0x1e0
   ? __pfx_kthread+0x10/0x10
   ret_from_fork+0x36e/0x5a0
   ? __pfx_ret_from_fork+0x10/0x10
   ? __switch_to+0x572/0xdd0
   ? __pfx_kthread+0x10/0x10
   ret_from_fork_asm+0x1a/0x30
   </TASK>

  Allocated by task 48:
   kasan_save_stack+0x33/0x60
   kasan_save_track+0x14/0x30
   __kasan_kmalloc+0x8f/0xa0
   __kmalloc_cache_noprof+0x158/0x370
   isert_cma_handler+0x1e3/0x2ae0
   cma_cm_event_handler+0x3e/0x240
   cma_ib_req_handler+0x17d9/0x4490
   cm_process_work+0x41/0x330
   cm_work_handler+0x5727/0xc160
   process_one_work+0x633/0x1030
   worker_thread+0x45b/0xd10
   kthread+0x2c6/0x3b0
   ret_from_fork+0x36e/0x5a0
   ret_from_fork_asm+0x1a/0x30

  Freed by task 184:
   kasan_save_stack+0x33/0x60
   kasan_save_track+0x14/0x30
   kasan_save_free_info+0x3b/0x60
   __kasan_slab_free+0x43/0x70
   kfree+0x121/0x380
   iscsit_close_connection+0x7cf/0x1e60
   iscsit_take_action_for_connection_exit+0x1b6/0x360
   iscsi_target_tx_thread+0x472/0x690
   kthread+0x2c6/0x3b0
   ret_from_fork+0x36e/0x5a0
   ret_from_fork_asm+0x1a/0x30

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
