External risk intelligence

Linux Kernel iSER Out-of-Bounds Read and Write Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-90414

The vulnerability affects iSER (iSCSI Extensions for RDMA), which is a storage networking protocol. While storage traffic is commonly segmented within internal networks or data centers and not directly exposed to the public internet, it is a network-level protocol that could be reachable in environments where iSCSI/RDMA infrastructure is inadvertently exposed or improperly segmented.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This critical vulnerability in the Linux kernel's iSER protocol could allow an attacker to read or write beyond designated memory buffers. While the direct impact depends on specific network configurations, it affects storage networking components and could lead to unauthorized access or modification of data. The main concern is confirming relevance and exposure within your environment.

  • Issue: Unauthorized memory access in Linux storage networking.
  • Why remember: Affects core data storage and network protocols.
  • Executive takeaway: Confirm if Linux iSER protocol is in use.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by sending specially crafted network traffic to a Linux system running the affected kernel. This traffic would target the iSER protocol, which is used for storage networking. By manipulating data segment declarations within this protocol, an attacker could cause the system to read beyond its allocated memory buffers.

  • Network access required.
  • Triggered by data segment manipulation.
  • Can lead to memory corruption.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an attacker to read or write data beyond allocated buffers within the Linux kernel's iSER protocol implementation. This could occur when an initiator declares a data segment size larger than the actual data received, leading to an out-of-bounds read or write. The affected system's data integrity and confidentiality could be compromised under these conditions.

  • Kernel memory and data integrity.
  • Over-declared data segment sizes.
  • Unauthorized memory access or modification.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in the Linux kernel's iSER protocol handler requires immediate attention from infrastructure and platform teams managing storage networks. The first crucial step is to identify all instances of the affected Linux kernel versions, determine their network exposure, and assess their business criticality. Once identified, work with the accountable owner to prioritize and plan remediation, coordinating with any relevant vendor-management teams if applicable.

  • Infrastructure and platform teams should own remediation.
  • Verify network reachability and business criticality.
  • Plan coordinated updates or mitigations.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the iSER component in the Linux kernel?

iSER stands for iSCSI Extensions for RDMA. It is a storage networking protocol used to move data between servers and storage devices efficiently by offloading network processing. In the Linux kernel, it allows storage traffic to bypass traditional network stacks, facilitating high-speed communication between initiators—the systems requesting data—and targets—the storage systems providing it.

What is the vulnerability in CVE-2026-90414?

This vulnerability is an out-of-bounds access flaw. It occurs because the iSER protocol fails to verify that the data declared by an initiator actually fits within the memory buffers reserved by the kernel. When this check is missing, the system may read from or write to unintended memory areas, potentially leading to unauthorized data disclosure or memory corruption.

How is this vulnerability triggered?

An attacker triggers the bug during the full feature phase of an iSCSI session. By manipulating the protocol handshake, the initiator declares a data segment size that exceeds the actual bytes sent or the predefined buffer limits. It is important to note that merely connecting to a system is not enough; the attacker must specifically supply malicious data length parameters to exploit the lack of validation.

Is my environment at risk from this CVE?

According to Halo Surface Signal, risk depends on how your storage infrastructure is configured. While iSER traffic is typically restricted to internal data center networks, you are more likely to be affected if your iSCSI or RDMA infrastructure is inadvertently exposed to broader network segments. You should evaluate if your Linux systems facilitate high-speed storage access across reachable network paths.

How should I respond to CVE-2026-90414?

Start by identifying all Linux systems in your environment that have the iSER protocol enabled. Once you have a list of these systems, assess their network connectivity and their role in handling storage traffic. Prioritize remediation by planning kernel updates or implementing compensating network controls to restrict unauthorized access to your iSER-enabled infrastructure.

References