CVE Database
/

CVE-2026-23216

Back to search

CVE-2026-23216

Published: Feb 18, 2026

Modified: May 11, 2026

PUBLISHED

Description

In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Fix use-after-free in iscsit_dec_conn_usage_count() In iscsit_dec_conn_usage_count(), the function calls complete() while holding the conn->conn_usage_lock. As soon as complete() is invoked, the waiter (such as iscsit_close_connection()) may wake up and proceed to free the iscsit_conn structure. If the waiter frees the memory before the current thread reaches spin_unlock_bh(), it results in a KASAN slab-use-after-free as the function attempts to release a lock within the already-freed connection structure. Fix this by releasing the spinlock before calling complete().

VendorProductVersions

Linux

Linux

affected
e48354ce078c079996f89d715dfa44814b4eba01 - < ba684191437380a07b27666eb4e72748be1ea201
affected
e48354ce078c079996f89d715dfa44814b4eba01 - < 8518f072fc92921418cd9ed4268dd4f3e9a8fd75
affected
e48354ce078c079996f89d715dfa44814b4eba01 - < 275016a551ba1a068a3bd6171b18611726b67110
affected
e48354ce078c079996f89d715dfa44814b4eba01 - < 73b487d44bf4f92942629d578381f89c326ff77f
affected
e48354ce078c079996f89d715dfa44814b4eba01 - < 48fe983e92de2c59d143fe38362ad17ba23ec7f3

+2 more versions

Linux

Linux

affected
3.1
unaffected
0 - < 3.1
unaffected
5.10.250 - <= 5.10.*
unaffected
5.15.200 - <= 5.15.*
unaffected
6.1.163 - <= 6.1.*

+4 more versions

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now