CVE-2026-63886
Gravedad CVSS v3.1:
CRÍTICA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
19/07/2026
Última modificación:
20/07/2026
Descripción
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
scsi: target: iscsi: Validate CHAP_R length before base64 decode<br />
<br />
chap_server_compute_hash() allocates client_digest as<br />
kzalloc(chap->digest_size) and then, for BASE64-encoded responses,<br />
passes chap_r directly to chap_base64_decode() without checking whether<br />
the input length could produce more than digest_size bytes of output.<br />
<br />
chap_base64_decode() writes to the destination unconditionally as long<br />
as there is input to consume. With MAX_RESPONSE_LENGTH set to 128 and<br />
the "0b" prefix stripped by extract_param(), up to 127 base64 characters<br />
can reach the decoder. 127 characters decode to 95 bytes. For SHA-256<br />
(digest_size=32) this overflows client_digest by 63 bytes; for MD5<br />
(digest_size=16) the overflow is 79 bytes.<br />
<br />
The length check at line 344 fires after the write has already happened.<br />
<br />
The HEX branch in the same switch statement already validates the length<br />
up front. Apply the same approach to the BASE64 branch: strip trailing<br />
base64 padding characters, then reject any input whose data length<br />
exceeds DIV_ROUND_UP(digest_size * 4, 3) before calling the decoder.<br />
<br />
Stripping trailing &#39;=&#39; before the comparison handles both padded and<br />
unpadded encodings. chap_base64_decode() already returns early on &#39;=&#39;,<br />
so the full original string is still passed to the decoder unchanged.<br />
<br />
The mutual CHAP path decodes CHAP_C into initiatorchg_binhex, which is<br />
kzalloc(CHAP_CHALLENGE_STR_LEN). extract_param() caps initiatorchg at<br />
CHAP_CHALLENGE_STR_LEN characters, so at most CHAP_CHALLENGE_STR_LEN-1<br />
base64 characters reach the decoder. The maximum decoded size,<br />
DIV_ROUND_UP((CHAP_CHALLENGE_STR_LEN-1) * 3, 4), is less than<br />
CHAP_CHALLENGE_STR_LEN, so no overflow is possible there. A comment is<br />
added at the call site to document this.
Impacto
Puntuación base 3.x
9.80
Gravedad 3.x
CRÍTICA
Referencias a soluciones, herramientas e información
- https://git.kernel.org/stable/c/4a3a19c98a8207ad08bec554703d90f2c34a8cc6
- https://git.kernel.org/stable/c/82454e6f21e56ea9a0a9de7d0ff7e1dfb83e34d6
- https://git.kernel.org/stable/c/85db7391310b1304d2dc8ae3b0b12105a9567147
- https://git.kernel.org/stable/c/bf154c657828ed05399bca5d98cf1611bb048b12
- https://git.kernel.org/stable/c/c04e85799356120209b351a148ac2db888d5ffd9
- https://git.kernel.org/stable/c/edd06675a02376ea8347dba7c29ad982ba5b36ee



