In the Linux kernel, the following vulnerability has been resolved:
scsi: target: core: Fix iSCSI ISID use-after-free in REGISTER AND MOVE
core_scsi3_emulate_pro_register_and_move() maps the PERSISTENT RESERVE OUT parameter list with transport_kmap_data_sg() and parses the destination TransportID with target_parse_pr_out_transport_id(). For an iSCSI TransportID (FORMAT CODE 01b), iscsi_parse_pr_out_transport_id() returns the ISID in iport_ptr as a raw pointer into that mapped buffer.
The function then unmaps the buffer with transport_kunmap_data_sg() before dereferencing iport_ptr in strcmp(), __core_scsi3_locate_pr_reg() and core_scsi3_alloc_registration(). When the parameter list spans more than one page (PARAMETER LIST LENGTH > 4096), transport_kmap_data_sg() uses vmap() and transport_kunmap_data_sg() does vunmap(), so the kernel virtual address backing iport_ptr is torn down and every subsequent dereference is a use-after-free read of the unmapped region.
Keep the parameter list mapped until iport_ptr is no longer needed: drop the early transport_kunmap_data_sg() and unmap once on the success path, right before returning. The error paths already unmap through the existing "if (buf) transport_kunmap_data_sg(cmd)" at the out: label, which now runs on every post-map error exit because buf is no longer cleared early. Only reads of the mapping happen while spinlocks are held; the map and unmap calls remain outside any lock. The sibling caller core_scsi3_decode_spec_i_port() already uses the buffer before unmapping it and is left unchanged.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux_2023 | — | Upgrade kernel-debuginfo-common-x86_64Upgrade bpftoolUpgrade kernel-modules-extraUpgrade kernelUpgrade kernel-debuginfoUpgrade bpftool-debuginfoUpgrade kernel-livepatch-6.1.180-225.360Upgrade python3-perf-debuginfoUpgrade kernel-toolsUpgrade kernel-develUpgrade kernel-tools-debuginfoUpgrade perf-debuginfoUpgrade kernel-headersUpgrade perfUpgrade kernel-modules-extra-commonUpgrade kernel-tools-develUpgrade python3-perfUpgrade kernel-debuginfo-common-aarch64 | Sep 1, 2026 | Aug 15, 2026 |
| Debian | — | Upgrade linux | Aug 16, 2026 | Aug 16, 2026 |
| Redhat_linux | — | No solution exists | Aug 19, 2026 | Aug 15, 2026 |
| Ubuntu | — | Upgrade linux-image-ibm-7.0Upgrade linux-image-7.0.0-1020-raspi-realtimeUpgrade linux-image-generic-64k-hwe-24.04Upgrade linux-image-nvidia-tegra-rtUpgrade linux-image-7.0.0-34-genericUpgrade linux-image-7.0.0-1013-aws-64kUpgrade linux-image-7.0.0-1012-oracleUpgrade linux-image-virtual-hwe-26.04Upgrade linux-image-nvidia-tegraUpgrade linux-image-ibmUpgrade linux-image-oracle-7.0Upgrade linux-image-raspiUpgrade linux-image-generic-hwe-24.04Upgrade linux-image-generic-64kUpgrade linux-image-6.8.0-1035-nvidia-tegraUpgrade linux-image-7.0.0-1020-raspiUpgrade linux-image-7.0.0-34-realtime-64kUpgrade linux-image-7.0.0-1012-oracle-64kUpgrade linux-image-awsUpgrade linux-image-virtual-7.0Upgrade linux-image-realtimeUpgrade linux-image-oracle-64kUpgrade linux-image-realtime-64k-hwe-26.04Upgrade linux-image-generic-hwe-26.04Upgrade linux-image-generic-64k-hwe-26.04Upgrade linux-image-raspi-realtime-7.0Upgrade linux-image-virtualUpgrade linux-image-aws-64kNo solution existsUpgrade linux-image-raspi-realtimeUpgrade linux-image-nvidia-tegra-rt-6.8Upgrade linux-image-realtime-64kUpgrade linux-image-nvidia-tegra-6.8Upgrade linux-image-realtime-64k-7.0Upgrade linux-image-oracleUpgrade linux-image-raspi-7.0Upgrade linux-image-aws-64k-7.0Upgrade linux-image-7.0.0-34-realtimeUpgrade linux-image-generic-7.0Upgrade linux-image-7.0.0-1013-awsUpgrade linux-image-virtual-hwe-24.04Upgrade linux-image-7.0.0-34-generic-64kUpgrade linux-image-6.8.0-1035-nvidia-tegra-rtUpgrade linux-image-realtime-hwe-26.04Upgrade linux-image-aws-7.0Upgrade linux-image-7.0.0-1014-ibmUpgrade linux-image-generic-64k-7.0Upgrade linux-image-genericUpgrade linux-image-realtime-7.0Upgrade linux-image-oracle-64k-7.0 | Sep 21, 2026 | Sep 18, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Aug 25, 2026 | Aug 15, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub