CVE-2025-38700
Published: Sep 4, 2025
Modified: May 12, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: scsi: libiscsi: Initialize iscsi_conn->dd_data only if memory is allocated In case of an ib_fast_reg_mr allocation failure during iSER setup, the machine hits a panic because iscsi_conn->dd_data is initialized unconditionally, even when no memory is allocated (dd_size == 0). This leads invalid pointer dereference during connection teardown. Fix by setting iscsi_conn->dd_data only if memory is actually allocated. Panic trace: ------------ iser: iser_create_fastreg_desc: Failed to allocate ib_fast_reg_mr err=-12 iser: iser_alloc_rx_descriptors: failed allocating rx descriptors / data buffers BUG: unable to handle page fault for address: fffffffffffffff8 RIP: 0010:swake_up_locked.part.5+0xa/0x40 Call Trace: complete+0x31/0x40 iscsi_iser_conn_stop+0x88/0xb0 [ib_iser] iscsi_stop_conn+0x66/0xc0 [scsi_transport_iscsi] iscsi_if_stop_conn+0x14a/0x150 [scsi_transport_iscsi] iscsi_if_rx+0x1135/0x1834 [scsi_transport_iscsi] ? netlink_lookup+0x12f/0x1b0 ? netlink_deliver_tap+0x2c/0x200 netlink_unicast+0x1ab/0x280 netlink_sendmsg+0x257/0x4f0 ? _copy_from_user+0x29/0x60 sock_sendmsg+0x5f/0x70
| Vendor | Product | Versions |
|---|---|---|
Linux | Linux | affected 5d91e209fb21fb9cc765729d4c6a85a9fb6c9187 - < f53af99f441ee79599d8df6113a7144d74cf9153affected 5d91e209fb21fb9cc765729d4c6a85a9fb6c9187 - < 9ea6d961566c7d762ed0204b06db05756fdda3b6affected 5d91e209fb21fb9cc765729d4c6a85a9fb6c9187 - < fd5aad080edb501ab5c84b7623d612d0e3033403affected 5d91e209fb21fb9cc765729d4c6a85a9fb6c9187 - < a145c269dc5380c063a20a0db7e6df2995962e9daffected 5d91e209fb21fb9cc765729d4c6a85a9fb6c9187 - < 66a373f50b4249d57f5a88c7be9676f9d5884865+4 more versions |
Linux | Linux | affected 2.6.27unaffected 0 - < 2.6.27unaffected 5.4.297 - <= 5.4.*unaffected 5.10.241 - <= 5.10.*unaffected 5.15.190 - <= 5.15.*+6 more versions |
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now