Buffer Overflow in Linux Kernel's iSCSI Target Feature
CVE-2026-90011

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
16 September 2026

What is CVE-2026-90011?

This vulnerability exists in the iSCSI target feature of the Linux kernel due to improper handling of login payloads. Specifically, when the DataSegmentLength of a login PDU exceeds a certain threshold, the allocated buffer does not account for a NUL terminator, leading to potential memory access violations. An unauthenticated attacker can exploit this weakness against a portal if CHAP authentication is not required, allowing for unauthorized access and manipulation of adjacent memory. To mitigate this issue, it is recommended to allocate an additional byte, ensuring that all buffers are properly terminated.

Affected Version(s)

Linux e48354ce078c079996f89d715dfa44814b4eba01 < 5fac79f248c37774d1dd761406f83d25ca6ff8e4

Linux e48354ce078c079996f89d715dfa44814b4eba01 < 6ddddcad436d8e6e619204d3c848147ff2f5bf1e

Linux e48354ce078c079996f89d715dfa44814b4eba01

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.