Buffer Overflow in Linux Kernel Affects iscsi_tcp Functionality
CVE-2026-74556
What is CVE-2026-74556?
A vulnerability exists in the Linux kernel's iscsi_tcp implementation, where a buffer overflow may occur when the SCSI Command Response data segment exceeds the allocated connection buffer size of 8192 bytes. Although certain PDU types correctly enforce length checks, the pathway for SCSI responses lacks this safeguard, which could result in an attacker exploiting this oversight. By manipulating the DataSegmentLength parameter, attackers can send a SCSI Response with a length that exceeds the buffer limit, potentially leading to memory corruption and unauthorized access.
Affected Version(s)
Linux a081c13e39b5c17052a7b46fafa61019c4c110ff
Linux a081c13e39b5c17052a7b46fafa61019c4c110ff < 084af0253673425ce2ae62e3c7f74f0dd023711b
Linux a081c13e39b5c17052a7b46fafa61019c4c110ff < 72815741715bd41556dac5eeb068bf0f8af06ee7