CVE-2026-23216
Published: Feb 18, 2026
Modified: May 11, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Fix use-after-free in iscsit_dec_conn_usage_count() In iscsit_dec_conn_usage_count(), the function calls complete() while holding the conn->conn_usage_lock. As soon as complete() is invoked, the waiter (such as iscsit_close_connection()) may wake up and proceed to free the iscsit_conn structure. If the waiter frees the memory before the current thread reaches spin_unlock_bh(), it results in a KASAN slab-use-after-free as the function attempts to release a lock within the already-freed connection structure. Fix this by releasing the spinlock before calling complete().
| Vendor | Product | Versions |
|---|---|---|
Linux | Linux | affected e48354ce078c079996f89d715dfa44814b4eba01 - < ba684191437380a07b27666eb4e72748be1ea201affected e48354ce078c079996f89d715dfa44814b4eba01 - < 8518f072fc92921418cd9ed4268dd4f3e9a8fd75affected e48354ce078c079996f89d715dfa44814b4eba01 - < 275016a551ba1a068a3bd6171b18611726b67110affected e48354ce078c079996f89d715dfa44814b4eba01 - < 73b487d44bf4f92942629d578381f89c326ff77faffected e48354ce078c079996f89d715dfa44814b4eba01 - < 48fe983e92de2c59d143fe38362ad17ba23ec7f3+2 more versions |
Linux | Linux | affected 3.1unaffected 0 - < 3.1unaffected 5.10.250 - <= 5.10.*unaffected 5.15.200 - <= 5.15.*unaffected 6.1.163 - <= 6.1.*+4 more versions |
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now