CVE-2026-74557
Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
15/08/2026
Última modificación:
15/08/2026
Descripción
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
scsi: libiscsi: Fix stale-data leak into the SCSI sense buffer<br />
<br />
iscsi_scsi_cmd_rsp() copies the sense data of a SCSI Response from the<br />
target-supplied data segment. The segment carries a 2-byte sense length<br />
followed by the sense bytes, so it must hold 2 + senselen bytes, but the<br />
bounds check only requires datalen >= senselen:<br />
<br />
senselen = get_unaligned_be16(data);<br />
if (datalen sense_buffer, data + 2,<br />
min_t(uint16_t, senselen, SCSI_SENSE_BUFFERSIZE));<br />
<br />
A target that returns a SCSI Response whose datalen equals senselen<br />
(with senselen data contents and end up in the command&#39;s sense buffer, which is<br />
returned to userspace.<br />
<br />
Account for the 2-byte sense length prefix in the check.
Impacto
Referencias a soluciones, herramientas e información
- https://git.kernel.org/stable/c/1f07a897d43c63e6c9458bf77450defef39b5833
- https://git.kernel.org/stable/c/3ef209ca0b4b68c75e9a814d90cc916026b5a6ac
- https://git.kernel.org/stable/c/60499924faf4ef97e84228c20515218ef121facf
- https://git.kernel.org/stable/c/7567f06abdefb1caf2d836107c4d08c5185c650e
- https://git.kernel.org/stable/c/98b87885de4b7f605533a2860685f5689fce8e82



