Linux Kernel Vulnerability in IB/iser for Data Commands
CVE-2026-98358
What is CVE-2026-98358?
A vulnerability exists in the Linux kernel's IB/iser subsystem affecting data write commands that utilize immediate data. Specifically, commands not properly registered can lead to a remote invalidation scenario where a malicious target can trigger a general protection fault. The issue arises because the function iser_check_remote_inv() mismanages unregistered command validation, resulting in potential faults when the invalidated descriptor is accessed. This flaw highlights the need for robust memory management and error handling in networking operations.
Affected Version(s)
Linux 59caaed7a72a0e3750dfb84636dae6b781559310 < 198e4db9add54a50cce60a5d80b8f0ee5456b65a
Linux 59caaed7a72a0e3750dfb84636dae6b781559310
Linux 59caaed7a72a0e3750dfb84636dae6b781559310 < 19ddd4af7fce9200e70882f622011e9dd130f427