KernelScan.io

CRITICAL Introduced in 3.1

iscsi-target LoginBuf Overflow

CVE-2026-63887

CVSS 9.8 / 10.0 NVD

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

KernelScan AI9.8CRITICAL

01

In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf iscsi_encode_text_output() concatenates "key=value\0" records into login->rsp_buf, an 8192-byte kzalloc(MAX_KEY_VALUE_PAIRS) buffer allocated in iscsit_alloc_login_setup_buffer(). The three sprintf() call sites in this function (lines 1398, 1411, 1424 in v7.1-rc2) never check the remaining buffer capacity: *length += sprintf(output_buf, "%s=%s", er->key, er->value); *length += 1; output_buf = textbuf + *length; The 8192-byte ceiling at iscsi_target_check_login_request() bounds the *input* Login PDU payload, but a single PDU can carry up to 2048 minimal four-byte "a=b\0" pairs, each unknown key expanding to a 16-byte "a=NotUnderstood\0" output record via iscsi_add_notunderstood_response(). 2048 * 16 = 32 KiB of output into an 8 KiB buffer, producing a ~24 KiB heap overrun in the kmalloc-8k slab. The fix introduces a static iscsi_encode_text_record() helper that uses snprintf() with a per-call bounds check against the remaining buffer, and threads a u32 textbuf_size parameter through iscsi_encode_text_output(). Both call sites in iscsi_target_handle_csg_zero() (PHASE_SECURITY) and iscsi_target_handle_csg_one() (PHASE_OPERATIONAL) pass MAX_KEY_VALUE_PAIRS. On overflow the encoder logs the condition, calls iscsi_release_extra_responses() to drop queued records, and returns -1; both caller sites now emit ISCSI_STATUS_CLS_INITIATOR_ERR / ISCSI_LOGIN_STATUS_INIT_ERR via iscsit_tx_login_rsp() before returning, so the initiator sees an explicit failed-login response rather than a silent connection drop. (Prior to this patch only the PHASE_OPERATIONAL caller did that; the PHASE_SECURITY caller is converted to the same shape.)

02

Engine v0.4.0

Risk summary

A remote unauthenticated attacker can send a crafted iSCSI Login PDU containing many minimal key-value pairs, causing the kernel iSCSI target to overflow an 8 KiB heap buffer by up to ~24 KiB during login response encoding. This heap overrun in the kmalloc-8k slab can lead to arbitrary kernel memory corruption, enabling remote code execution or kernel crash without any authentication. Any system running the Linux kernel iSCSI target (LIO) and accepting iSCSI connections is affected.

Affecteddrivers/target/iscsi/iscsi_target_parameters.c (iSCSI target login negotiation)

Vulnerability analysis

The vulnerability is a heap buffer overflow in iscsi_encode_text_output() in the Linux kernel iSCSI target implementation. The root cause is that three sprintf() call sites in this function write 'key=value\0' records into login->rsp_buf, an 8192-byte kzalloc buffer, without ever checking remaining capacity. While the input Login PDU payload is bounded to 8192 bytes, a single PDU can contain up to 2048 minimal 4-byte 'a=b\0' pairs. Each unknown key triggers iscsi_add_notunderstood_response() which expands it to a 16-byte 'a=NotUnderstood\0' output record, yielding 2048*16=32768 bytes of output into an 8192-byte buffer — a ~24 KiB overrun in the kmalloc-8k slab. The fix introduces a static iscsi_encode_text_record() helper using snprintf() with per-call bounds checking against remaining buffer space, threads a textbuf_size parameter through iscsi_encode_text_output(), and on overflow logs the condition, releases queued records, and returns -1 so callers send an explicit ISCSI_LOGIN_STATUS_INIT_ERR response. The attack is fully network-reachable with no authentication required, as the overflow occurs during the login phase before any credentials are validated.

03

BranchIntroducedFixed inPatch commit
6.63.16.6.1434e9f0c4a645c
6.123.16.12.9330bf335e8fe1
6.183.16.18.35594a40360012
7.03.17.0.1226e4a304b7e6
mainline3.17.1bf33e01f8838
5.103.15.10.259cb84e974fb17
6.13.16.1.176efe633e600a0
5.153.15.15.210b19382dfc6e7