Linux Kernel Vulnerability in iSCSI Target for Deferred Control PDUs
CVE-2026-98357
What is CVE-2026-98357?
A vulnerability has been identified in the Linux kernel related to the iSCSI Target implementation, specifically affecting deferred control PDU completions. The issue arises from the improper synchronization of operations, leading to potential memory corruption. The function 'isert_send_done()' hands off completions to a worker queue and returns, which may lead to a race condition during connection teardown. If a connection is released while the completion handler is still processing, this could dereference freed memory, causing instability or crashes. This vulnerability underscores the importance of adequate synchronization in multi-threaded environments to prevent use-after-free errors.
Affected Version(s)
Linux b8d26b3be8b33682cf163274ed07479a70554633
Linux b8d26b3be8b33682cf163274ed07479a70554633
Linux b8d26b3be8b33682cf163274ed07479a70554633 < 0e230917670c6e6fe3243abfa11299fcbe05b1f4