Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2026-74556

scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer
Back to all
CVE

CVE-2026-74556

scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer

In the Linux kernel, the following vulnerability has been resolved:

scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer

iscsitcphdr_dissect() receives the data segment of several PDU types

into the fixed-size conn->data buffer, which is allocated for

ISCSIDEFMAXRECVSEGLEN (8192) bytes.  For the LOGINRSP, TEXT_RSP,

REJECT and ASYNC_EVENT opcodes the dissect path already rejects a PDU

whose DataSegmentLength exceeds that buffer.

The SCSI Command Response (ISCSIOPSCSICMDRSP) path also copies its

data segment (sense/response data) into conn->data via

iscsitcpdatarecvprep(), but it does so without the same check.  The

only upstream bound on in.datalen is conn->maxrecvdlength, the

initiator's advertised MaxRecvDataSegmentLength, which is commonly

negotiated well above 8192 (open-iscsi defaults to 262144).  A target

that returns a SCSI Response with a DataSegmentLength between 8193 and

maxrecvdlength therefore overflows the 8192-byte conn->data buffer.

Once the same bound applies, ISCSIOPSCSICMDRSP is handled exactly

like those responses: bound the data segment, receive it into conn->data

when present, and otherwise complete the PDU with no data.  Fold the

opcode into that case group rather than duplicating the check.

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
9.8
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
0
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
-

Related Resources

No items found.

References

https://git.kernel.org/stable/c/084af0253673425ce2ae62e3c7f74f0dd023711b, https://git.kernel.org/stable/c/72815741715bd41556dac5eeb068bf0f8af06ee7, https://git.kernel.org/stable/c/a51812842084fd390590ab8dc0431f10c73ddc56, https://git.kernel.org/stable/c/a8f94cc9f0e5759252551be3a172960c57f21f54, https://git.kernel.org/stable/c/b0aa3e8e2ab4ca92adb28a3ef41873b3363b8676, https://git.kernel.org/stable/c/c1dea15f819cded9b3faf58f8bec72323568b6e6, https://git.kernel.org/stable/c/c97b5265cc47775f77fd2a23d6bde0426997b233, https://git.kernel.org/stable/c/f1a3a51fc5dba0e99532379665069f1700da6b44, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74556.json, https://nvd.nist.gov/vuln/detail/CVE-2026-74556, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Severity

9.8

CVSS Score
0
10

Basic Information

Base CVSS
9.8
EPSS Probability
0.00399%
EPSS Percentile
0.32837%
Introduced Version
a081c13e39b5c17052a7b46fafa61019c4c110ff,2.6.29,5.11.0,5.16.0,6.2.0,6.7.0,6.13.0,6.19.0,0
Fix Available
c1dea15f819cded9b3faf58f8bec72323568b6e6,5.10.265,5.15.216,6.1.183,6.6.151,6.12.103,6.18.44,7.1.8,6.12.105-1

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading