External risk intelligence

Linux Kernel iSCSI Target Buffer Over-read Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-90011

This vulnerability affects the Linux kernel iSCSI target implementation. iSCSI portals are typically network-accessible services designed to handle connections from remote initiators. While security controls like CHAP may be applied, the interface itself functions as an externally reachable protocol service in many storage networking deployments.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability in the Linux kernel's iSCSI target implementation could allow an unauthenticated initiator to access memory outside of its intended buffer. This issue arises from how the login payload is handled, potentially leading to unintended memory writes that could impact adjacent data. The concern is primarily centered on confirming whether this specific technology is in use and exposed within your environment.

  • A technical flaw allows unauthorized memory access.
  • iSCSI systems could be at risk of data corruption.
  • Confirm relevance and exposure of iSCSI services.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker can send a specially crafted login request to a Linux kernel's iSCSI target. This request exploits a missing terminator byte in the login payload buffer, causing subsequent string manipulation functions to read past the buffer's boundary. This could lead to memory corruption and potential system compromise.

  • Unauthenticated initiator access required.
  • Login request triggers buffer over-read.
  • Memory corruption, potential system compromise.

Live Threat

Current exploitation, exposure, and threat context

An unauthenticated initiator could trigger a buffer overflow in the Linux kernel's iSCSI target when CHAP authentication is configured. This occurs because a login request may not be null-terminated, leading to memory corruption when processed as a C string. The overflow could affect adjacent slab memory.

  • Kernel memory could be corrupted.
  • Malformed login requests could trigger it.
  • System instability or crashes may result.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability impacts the Linux kernel's iSCSI target, likely managed by infrastructure or platform teams responsible for storage services. The first action should be to identify all iSCSI target instances, determine their network reachability and business criticality, and then locate the specific system or service owner to plan remediation.

  • Infrastructure or platform teams own resolution.
  • Verify iSCSI target network exposure.
  • Plan vendor coordination and patching.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Linux kernel iSCSI target?

The Linux kernel iSCSI target is a software component that allows a server to act as a storage provider, known as a target, over a network. Clients, or initiators, connect to these targets to access block storage devices as if they were locally attached. It is widely used in enterprise data centers to enable remote disk access, high-performance storage area networks, and flexible cloud infrastructure setups.

How does CVE-2026-90011 represent a memory handling weakness?

This vulnerability is an out-of-bounds memory read error. When the iSCSI login buffer is completely filled with data, it lacks a required NUL terminator byte. Because the system treats this buffer as a C-style string during subsequent processing, string-handling functions continue reading past the intended memory boundary. This causes the software to access adjacent memory, potentially leading to system instability or information exposure.

Does any configuration avoid this vulnerability?

The vulnerability requires the target to be configured for CHAP authentication. If the iSCSI portal is set up to require no authentication—where the system forces the authentication method to 'None'—the specific code path that processes these CHAP login parameters is bypassed, and the bug is not triggered.

Is my system at risk according to Halo Surface Signal?

Halo Surface Signal identifies this as a 'Likely' concern because iSCSI portals are typically designed to be network-accessible services for remote initiators. If your infrastructure hosts iSCSI target services that are reachable over the network, they may be exposed to unauthorized initiators. You should prioritize inventorying these services, especially those accessible outside of restricted management segments.

What is the first step to address this CVE?

Begin by identifying all systems running iSCSI target services within your environment. Once mapped, confirm their network accessibility and business criticality. Since this involves a kernel-level issue, consult with your infrastructure or platform engineering teams to track the availability of patched kernel updates from your Linux distribution vendor, which will introduce the necessary buffer allocation fix.

References