CVE-2026-63888
In the Linux kernel, the following vulnerability has been resolved:
scsi: target: iscsi: Fix CRC overread and double-free in iscsithandletext_cmd()
Two latent bugs in the Text-phase handler, both present since the
original LIO integration in commit e48354ce078c ("iscsi-target: Add
iSCSI fabric support for target v4.1"):
- DataDigest CRC buffer overread (4 bytes past text_in).
textin is kzalloc()'d at ALIGN(payloadlength, 4). rx_size is then
incremented by ISCSICRCLEN to make room for the received DataDigest
in the iovec, but the same (now-bumped) rx_size is passed as the
buffer length to iscsitcrcbuf():
if (conn->conn_ops->DataDigest) {
...
rxsize += ISCSICRC_LEN;
}
...
if (conn->conn_ops->DataDigest) {
datacrc = iscsitcrcbuf(textin, rx_size, 0, NULL);
iscsitcrcbuf() walks rxsize bytes of textin with crc32c(), so
when DataDigest is negotiated it reads 4 bytes past the end of the
text_in allocation. KASAN reproduces this directly on the unpatched
mainline tree as slab-out-of-bounds in crc32c() called from the Text
PDU path. The OOB bytes feed crc32c() and are then compared against
the initiator-supplied checksum, so the value does not flow back to
the attacker, but the kernel does read past the buffer on every Text
PDU with DataDigest=CRC32C.
Fix by passing the actual padded payload length
(ALIGN(payload_length, 4)) that was used for the kzalloc().
- Stale cmd->textinptr re-free (double-free) on ERL>0 bad DataDigest
drop.
On DataDigest mismatch with ErrorRecoveryLevel > 0 the handler
silently drops the PDU and lets the initiator plug the CmdSN gap:
kfree(text_in);
return 0;
cmd->textinptr still points at the freed buffer. The next Text
Request on the same ITT re-enters iscsitsetuptext_cmd(), which
unconditionally does
kfree(cmd->textinptr);
cmd->textinptr = NULL;
freeing the same pointer a second time. Session teardown via
iscsitreleasecmd() has the same shape and hits the same double-free
if the connection is dropped before a second Text Request arrives.
On an unmodified mainline tree the bug-1 CRC overread fires first on
the initial valid Text Request and perturbs the subsequent state, so
#4 was isolated by building a kernel with only the bug-1 hunk of this
patch applied plus temporary printk() observability around the three
relevant kfree() sites. The observability prints are not part of
this patch. On that build, a three-PDU Text Request sequence after
login produces two back-to-back splats:
BUG: KASAN: double-free in iscsitsetuptext_cmd+0x??
BUG: KASAN: double-free in iscsitreleasecmd+0x??
showing the same pointer freed in the ERL>0 drop path and again in
iscsitsetuptext_cmd() (next Text Request on the same ITT) and once
more in iscsitreleasecmd() (session teardown). On distro kernels
with CONFIGSLABFREELIST_HARDENED=y (default) the double-free
becomes a remote kernel BUG(); on non-hardened kernels it corrupts
the slab freelist.
Fix by clearing cmd->textinptr after the kfree() in the ERL>0 drop
path. With both hunks applied #4 is directly observable on the stock
tree without observability printks; fixing bug-1 alone would mask #4
less, not more, so the hunks are submitted together.
Both fixes are one-liners. The Text PDU state machine is unchanged and
the wire protocol is unaffected.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://git.kernel.org/stable/c/5118ea225fe63b44207ba88047e4866e1ea43812, https://git.kernel.org/stable/c/6e22a1cdcc8277af4acc43710577157b77a02c5d, https://git.kernel.org/stable/c/778c2ab142c625a8a8afa570e0f9b7873f445d99, https://git.kernel.org/stable/c/89c81d1228c00fa6dd91de6c1c5aa1ef8a7875e3, https://git.kernel.org/stable/c/badf178b76b0690851df00f4ca9cf2eb8eb0f963, https://git.kernel.org/stable/c/d3e9b79aa794f7a23e82de4d710e7d2df610e349, https://git.kernel.org/stable/c/ec9f19d52074a191ed1756ed4a7d39fff1a2085c, https://git.kernel.org/stable/c/f7948af0dd03de84079dcd4dc215a69fd6fbb95d, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63888.json, https://nvd.nist.gov/vuln/detail/CVE-2026-63888, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git