CVE-2026-98358: IB/iser: reject a remote invalidation of an unregistered direction
IB/iser: reject a remote invalidation of an unregistered direction
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Linux kernel systems using the IB/iser initiator path are exposed when communicating with an iSER target. The triggering condition involves a write command whose data is sent entirely as immediate data.
What does an attacker or malicious peer need to do to trigger the fault?
The iSER target must respond to the affected write command with IB_WR_SEND_WITH_INV, remotely invalidating the outbound direction even though that direction was never registered. This can cause the initiator to dereference a NULL descriptor and fault.
What happens when the vulnerable initiator receives this invalidation?
It can hit a NULL-pointer dereference while accessing desc->sig_protected, resulting in a general protection fault. The resolved behavior is to terminate the connection when an unregistered direction is remotely invalidated.
How can administrators determine whether they need the fix?
Review whether the system uses the Linux kernel IB/iser initiator and sends write commands entirely as immediate data to iSER targets. Kernel logs showing a KASAN NULL-pointer dereference in iser_inv_desc or iser_check_remote_inv are evidence of the affected failure path.