{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "7.2.8-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  IB/isert: wait for deferred control PDU completions before releasing the connection  isert_send_done() hands ISTATE_SEND_TASKMGTRSP, ISTATE_SEND_REJECT and ISTATE_SEND_TEXTRSP completions off to isert_comp_wq and returns.  The work item then runs isert_completion_put() -\u003e isert_put_cmd(), which reads isert_conn-\u003econn and takes conn-\u003ecmd_lock.  Nothing orders that work item against teardown.  isert_wait_conn() queues isert_release_work, which frees isert_conn, and iscsit_close_connection() frees the iscsit_conn right after it returns, so the queued work can run against freed memory.  Count the deferred control PDU completions per connection and let isert_wait_conn() wait for them before the release work is queued.  ISTATE_SEND_LOGOUTRSP is deliberately not counted: that branch runs iscsit_logout_post_handler(), which ends up waiting for conn-\u003econn_wait_comp, and that completion is only sent by iscsit_close_connection() after it has called iscsit_wait_conn(). Waiting for it here would deadlock.  Its wait stays the existing isert_wait4logout().  The splat below is from a kernel with tracing printk()s and an msleep(200) injected into isert_do_control_comp() to widen the window:    BUG: KASAN: slab-use-after-free in isert_put_cmd+0x53d/0x620   Read of size 8 at addr ffff8881054f1038 by task kworker/u17:1/182    CPU: 0 UID: 0 PID: 182 Comm: kworker/u17:1 Tainted: G    B               7.2.0-rc5-TWIDE-gb8babf08acc7 #1 PREEMPT(lazy)   Tainted: [B]=BAD_PAGE   Hardware name: QEMU Ubuntu 24.04 PC v2 (i440FX + PIIX, arch_caps fix, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014   Workqueue: isert_comp_wq isert_do_control_comp   Call Trace:    \u003cTASK\u003e    dump_stack_lvl+0x53/0x70    print_report+0xd0/0x630    ? __pfx__raw_spin_lock_irqsave+0x10/0x10    ? _raw_spin_unlock_irqrestore+0x3e/0x70    ? isert_put_cmd+0x53d/0x620    kasan_report+0xce/0x100    ? isert_put_cmd+0x53d/0x620    isert_put_cmd+0x53d/0x620    ? isert_completion_put+0x305/0x330    ? isert_do_control_comp+0x2ef/0x310    process_one_work+0x633/0x1030    ? assign_work+0x11d/0x370    worker_thread+0x45b/0xd10    ? __pfx_worker_thread+0x10/0x10    ? __pfx_worker_thread+0x10/0x10    kthread+0x2c6/0x3b0    ? recalc_sigpending+0x15c/0x1e0    ? __pfx_kthread+0x10/0x10    ret_from_fork+0x36e/0x5a0    ? __pfx_ret_from_fork+0x10/0x10    ? __switch_to+0x572/0xdd0    ? __pfx_kthread+0x10/0x10    ret_from_fork_asm+0x1a/0x30    \u003c/TASK\u003e    Allocated by task 48:    kasan_save_stack+0x33/0x60    kasan_save_track+0x14/0x30    __kasan_kmalloc+0x8f/0xa0    __kmalloc_cache_noprof+0x158/0x370    isert_cma_handler+0x1e3/0x2ae0    cma_cm_event_handler+0x3e/0x240    cma_ib_req_handler+0x17d9/0x4490    cm_process_work+0x41/0x330    cm_work_handler+0x5727/0xc160    process_one_work+0x633/0x1030    worker_thread+0x45b/0xd10    kthread+0x2c6/0x3b0    ret_from_fork+0x36e/0x5a0    ret_from_fork_asm+0x1a/0x30    Freed by task 184:    kasan_save_stack+0x33/0x60    kasan_save_track+0x14/0x30    kasan_save_free_info+0x3b/0x60    __kasan_slab_free+0x43/0x70    kfree+0x121/0x380    iscsit_close_connection+0x7cf/0x1e60    iscsit_take_action_for_connection_exit+0x1b6/0x360    iscsi_target_tx_thread+0x472/0x690    kthread+0x2c6/0x3b0    ret_from_fork+0x36e/0x5a0    ret_from_fork_asm+0x1a/0x30",
  "id": "DEBIAN-CVE-2026-98357",
  "modified": "2026-10-07T04:47:40.871298720Z",
  "published": "2026-10-06T09:18:29.293Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-98357"
    }
  ],
  "upstream": [
    "CVE-2026-98357"
  ]
}