Linux Kernel Vulnerability in iSCSI Target for Deferred Control PDUs
CVE-2026-98357

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
6 October 2026

What is CVE-2026-98357?

A vulnerability has been identified in the Linux kernel related to the iSCSI Target implementation, specifically affecting deferred control PDU completions. The issue arises from the improper synchronization of operations, leading to potential memory corruption. The function 'isert_send_done()' hands off completions to a worker queue and returns, which may lead to a race condition during connection teardown. If a connection is released while the completion handler is still processing, this could dereference freed memory, causing instability or crashes. This vulnerability underscores the importance of adequate synchronization in multi-threaded environments to prevent use-after-free errors.

Affected Version(s)

Linux b8d26b3be8b33682cf163274ed07479a70554633

Linux b8d26b3be8b33682cf163274ed07479a70554633

Linux b8d26b3be8b33682cf163274ed07479a70554633 < 0e230917670c6e6fe3243abfa11299fcbe05b1f4

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.