← All Advisories

CVE-2026-98357

Last refreshed2026-10-09

Status: UPDATED  |  Advisory ID: CVE-2026-98357

Key Details

CVECVE-2026-98357
CVSS Score / Version8.1 (High) / CVSS v3.1
Updated2026-10-07
CVSS VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is network; attack complexity is high; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsLinux Kernel

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux Kernel
SubsystemsOT Supporting Infrastructure
SectorsAll Sectors

What to Know

In the Linux kernel, the following vulnerability has been resolved:

IB/isert: wait for deferred control PDU completions before releasing the connection

isert_send_done() hands ISTATE_SEND_TASKMGTRSP, ISTATE_SEND_REJECT and

ISTATE_SEND_TEXTRSP completions off to isert_comp_wq and returns. The work

item then runs isert_completion_put() -> isert_put_cmd(), which reads

isert_conn->conn and takes conn->cmd_lock.

Nothing orders that work item against teardown. isert_wait_conn() queues

isert_release_work, which frees isert_conn, and iscsit_close_connection()

frees the iscsit_conn right after it returns, so the queued work can run

against freed memory.

Count the deferred control PDU completions per connection and let

isert_wait_conn() wait for them before the release work is queued.

ISTATE_SEND_LOGOUTRSP is deliberately not counted: that branch runs

iscsit_logout_post_handler(), which ends up waiting for

conn->conn_wait_comp, and that completion is only sent by

iscsit_close_connection() after it has called iscsit_wait_conn().

Waiting for it here would deadlock. Its wait stays the existing

isert_wait4logout().

The splat below is from a kernel with tracing printk()s and an msleep(200)

injected into isert_do_control_comp() to widen the window:

BUG: KASAN: slab-use-after-free in isert_put_cmd+0x53d/0x620

Read of size 8 at addr ffff8881054f1038 by task kworker/u17:1/182

CPU: 0 UID: 0 PID: 182 Comm: kworker/u17:1 Tainted: G B 7.2.0-rc5-TWIDE-gb8babf08acc7 #1 PREEMPT(lazy)

Tainted: [B]=BAD_PAGE

Hardware name: QEMU Ubuntu 24.04 PC v2 (i440FX + PIIX, arch_caps fix, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014

Workqueue: isert_comp_wq isert_do_control_comp

Call Trace:

<TASK>

dump_stack_lvl+0x53/0x70

print_report+0xd0/0x630

? __pfx__raw_spin_lock_irqsave+0x10/0x10

? _raw_spin_unlock_irqrestore+0x3e/0x70

? isert_put_cmd+0x53d/0x620

kasan_report+0xce/0x100

? isert_put_cmd+0x53d/0x620

isert_put_cmd+0x53d/0x620

? isert_completion_put+0x305/0x330

? isert_do_control_comp+0x2ef/0x310

process_one_work+0x633/0x1030

? assign_work+0x11d/0x370

worker_thread+0x45b/0xd10

? __pfx_worker_thread+0x10/0x10

? __pfx_worker_thread+0x10/0x10

kthread+0x2c6/0x3b0

? recalc_sigpending+0x15c/0x1e0

? __pfx_kthread+0x10/0x10

ret_from_fork+0x36e/0x5a0

? __pfx_ret_from_fork+0x10/0x10

? __switch_to+0x572/0xdd0

? __pfx_kthread+0x10/0x10

ret_from_fork_asm+0x1a/0x30

</TASK>

Allocated by task 48:

kasan_save_stack+0x33/0x60

kasan_save_track+0x14/0x30

__kasan_kmalloc+0x8f/0xa0

__kmalloc_cache_noprof+0x158/0x370

isert_cma_handler+0x1e3/0x2ae0

cma_cm_event_handler+0x3e/0x240

cma_ib_req_handler+0x17d9/0x4490

cm_process_work+0x41/0x330

cm_work_handler+0x5727/0xc160

process_one_work+0x633/0x1030

worker_thread+0x45b/0xd10

kthread+0x2c6/0x3b0

ret_from_fork+0x36e/0x5a0

ret_from_fork_asm+0x1a/0x30

Freed by task 184:

kasan_save_stack+0x33/0x60

kasan_save_track+0x14/0x30

kasan_save_free_info+0x3b/0x60

__kasan_slab_free+0x43/0x70

kfree+0x121/0x380

iscsit_close_connection+0x7cf/0x1e60

iscsit_take_action_for_connection_exit+0x1b6/0x360

iscsi_target_tx_thread+0x472/0x690

kthread+0x2c6/0x3b0

ret_from_fork+0x36e/0x5a0

ret_from_fork_asm+0x1a/0x30 (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-98357
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-98357