External risk intelligence

Linux Kernel iSER Login PDU Handling Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-90413

The vulnerability affects the iSCSI Extensions for RDMA (iSER) target component within the Linux kernel. iSCSI is primarily deployed within private, high-performance, or storage area networks (SANs) and is not intended or typically configured for direct exposure to the public internet. While network-reachable within internal infrastructure, public-facing deployments of iSER are uncommon.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability was identified in the Linux kernel's iSCSI Extensions for RDMA (iSER) component that could allow an attacker to read beyond allocated memory buffers. This could lead to potential system instability or information disclosure. The main concern is confirming if this specific component is in use and exposed.

  • An issue exists where data might be read improperly.
  • This could affect systems using specific storage network technology.
  • Confirm relevance and potential exposure of affected systems.

Attack Path

How an attacker could exploit the issue

An attacker could target the iSCSI Extensions for RDMA (iSER) component within the Linux kernel. This vulnerability allows an unauthenticated attacker to send specially crafted login packets that declare more data than is actually received. This can lead to the kernel reading beyond the allocated buffer, potentially causing a crash or other system instability.

  • Entry condition: Network access to the vulnerable iSER component.
  • Trigger point: Sending a login PDU with an oversized data declaration.
  • Resulting risk: System instability or crash.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability in the Linux kernel's iSER (iSCSI Extensions for RDMA) target component could allow an unauthenticated, remote attacker to cause a heap buffer overflow when processing login PDUs. This could potentially lead to a system crash or disclosure of memory contents under specific network conditions.

  • Kernel memory could be corrupted.
  • Malformed login PDUs may be sent.
  • System instability or memory leaks may occur.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Linux kernel's iSCSI Extensions for RDMA (iSER) component is affected by this vulnerability. Infrastructure or platform teams managing Linux systems that implement iSER should lead the response by first identifying all instances of the affected kernel component. Confirming reachability, business criticality, and the accountable owner is essential before planning remediation.

  • Infrastructure or platform teams own the issue.
  • Verify iSER reachability and system criticality.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the iSER component in the Linux kernel?

iSER (iSCSI Extensions for RDMA) is a storage networking protocol component. It allows Linux systems to access remote block storage devices over high-speed networks using Remote Direct Memory Access (RDMA) to reduce latency and CPU overhead, typically within specialized storage area networks.

What kind of vulnerability is CVE-2026-90413?

This is a heap-based out-of-bounds read vulnerability. It occurs because the kernel fails to verify that the length of data declared in a login packet matches the amount of data actually received. This logic error allows the system to read memory outside the intended buffer, which can lead to system instability or the disclosure of sensitive kernel memory.

How can an attacker trigger this vulnerability?

An attacker can trigger this by sending a malformed iSCSI login packet that declares a data length greater than the actual data transmitted. If the system does not reject this mismatched packet, the kernel attempts to process the declared length, causing it to read past the end of the allocated memory buffer. Standard iSCSI traffic handled via TCP is not affected by this specific issue.

Is my system at risk of CVE-2026-90413?

Risk depends on whether you utilize iSER. According to Halo Surface Signal, iSER is typically deployed within private, high-performance storage networks rather than on the public internet. While it is network-reachable within your internal infrastructure, you should assess whether any iSER-enabled endpoints are exposed to untrusted network segments.

What are the first steps to address this vulnerability?

Begin by identifying all Linux systems in your environment that have the iSER component enabled. Once identified, evaluate the network reachability of these systems to understand the potential for unauthorized access. Prioritize these systems based on their business criticality and consult your distribution's security updates to apply the necessary kernel patches.

References