CVE-2026-90294

HIGHPre-NVD 7.57.5—
EchelonGraph scoreHIGH confidence

Score 7.5 from GitHub Security Advisory (severity: HIGH) published 2026-09-17. A secondary CVSS source baseline 7.5; sources differ by 0.0.

Triggered by: GitHub Security Advisory CVSS
Sources: epss, ghsa, secondary
Trending — 3 sources updated this week
7.5EG
EchelonGraph verdictPlan mitigationSerious severity, but no confirmed exploitation yet.
  • High severity, but no confirmed exploitation yet
CISA-KEV: Not listedEPSS PROB: 0.7%CVSS: 7.5Exploit: None knownExposed services: Not assessed

No fix is confirmed yet — apply a workaround or compensating control (WAF / firewall / segmentation) and watch for the fix.

In the Linux kernel, the following vulnerability has been resolved:

IB/isert: delay the final Login Response until the session is registered

isert_put_login_tx() puts the final Login Response on the wire before __transport_register_session(), which iscsi_post_login_handler() reaches only after iscsi_target_do_login() returns. An initiator that issues a SCSI command as soon as it sees that response can have it executed against an se_session whose se_tpg is still NULL, and the ib-comp-wq worker oopses on the NULL dereference.

Oops: general protection fault, probably for non-canonical address 0xdffffc000000000f: 0000 [#1] SMP KASAN NOPTI KASAN: null-ptr-deref in range [0x0000000000000078-0x000000000000007f] CPU: 0 UID: 0 PID: 178 Comm: kworker/0:1H Not tainted 7.2.0-rc5-V2CTL-gf5098b6bae76 #10 PREEMPT(lazy) Hardware name: QEMU Ubuntu 24.04 PC v2 (i440FX + PIIX, arch_caps fix, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014 Workqueue: ib-comp-wq ib_cq_poll_work RIP: 0010:target_submit+0xbe/0x390 Code: fa 48 c1 ea 03 80 3c 02 00 0f 85 89 02 00 00 48 b8 00 00 00 00 00 fc ff df 4d 8b 64 24 18 49 8d 7c 24 78 48 89 fa 48 c1 ea 03 <80> 3c 02 00 0f 85 5a 02 00 00 48 8d 7b 78 4d 8b 6c 24 78 48 b8 00 RSP: 0018:ffff8881058cfa78 EFLAGS: 00010206 RAX: dffffc0000000000 RBX: ffff88810c78c6f0 RCX: ffffffff964bb363 RDX: 000000000000000f RSI: 00000000fffffe00 RDI: 0000000000000078 RBP: 1ffff11020b19f52 R08: 0000000000000001 R09: ffffed1020b19f52 R10: 0000000000000003 R11: ffff88810596c000 R12: 0000000000000000 R13: ffff88810c61b000 R14: ffff88810c6a3400 R15: ffff88810c61b044 FS: 0000000000000000(0000) GS:ffff8881822b2000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00007f1f1b83c000 CR3: 000000006fe72001 CR4: 0000000000770ef0 PKRU: 55555554 Call Trace: ? __pfx__raw_spin_lock_bh+0x10/0x10 ? __pfx_target_submit+0x10/0x10 ? mutex_lock+0x81/0xe0 ? __pfx_mutex_lock+0x10/0x10 ? iscsit_execute_cmd+0x650/0x850 iscsit_sequence_cmd+0x186/0x3d0 iscsit_process_scsi_cmd+0x87/0x300 isert_recv_done+0x1002/0x2390 ? __pfx_isert_recv_done+0x10/0x10 ? rxe_poll_cq+0x253/0x3d0 ? finish_task_switch.isra.0+0x1dc/0xa70 __ib_process_cq+0xe1/0x390 ib_cq_poll_work+0x46/0x150 process_one_work+0x633/0x1030 ? assign_work+0x11d/0x370 worker_thread+0x45b/0xd10 ? __pfx_worker_thread+0x10/0x10 ? __pfx_worker_thread+0x10/0x10 kthread+0x2c6/0x3b0 ? recalc_sigpending+0x15c/0x1e0 ? __pfx_kthread+0x10/0x10 ret_from_fork+0x36e/0x5a0 ? __pfx_ret_from_fork+0x10/0x10 ? __switch_to+0x572/0xdd0 ? __pfx_kthread+0x10/0x10 ret_from_fork_asm+0x1a/0x30 Modules linked in: ---[ end trace 0000000000000000 ]---

Delay the final Login Response instead. isert_get_rx_pdu() runs from iscsi_target_rx_thread() after conn->rx_login_comp, completed by iscsi_post_login_handler() after __transport_register_session(); iscsi-TCP and cxgbit already take PDUs from that thread, isert alone does not. The buffers are still posted first, so the initiator's first command does not meet an empty receive queue and nothing depends on RNR flow control, and the header and payload live in isert_conn, not in the struct iscsi_login that iscsi_target_nego_release() frees first.

Over rxe, 400 login cycles per run, the oops appeared in 10 of 20 unpatched runs and in none of 20 runs with this patch. An initiator that never waits is handled by the next patch.

Not tested: iWARP, discovery sessions over iSER, and real HCAs.

CVSS v3
7.5
EG Score
7.5HIGHhigh confidence
EG Risk
39
EG Risk 39/100CISA SSVC

EG Risk is EchelonGraph's 0–100 priority score: it fuses intrinsic severity with real-world exploitation and automatability so you can rank equal-severity CVEs and fix the most dangerous first. Higher = act sooner. Distinct from the 0–10 EG Score (severity).

How it’s computed
Severity75% × 45%
Exploitation1% × 40%
Automatability30% × 15%
CISA SSVC: Track at low or medium mission impact; Track or Attend at high (mission-essential systems).
Action: No fix is confirmed yet. Restrict network exposure of the affected system or apply the vendor's mitigation within your standard update timelines at low or medium mission impact and sooner than that at high, and watch the vendor's advisory for the fix.
EPSS PROB
0.7%
EPSS %ILE
52nd
KEV
Not listed

CISA SSVCTrack at low or medium mission impact; Track or Attend at high (mission-essential systems).

No fix is confirmed yet. Restrict network exposure of the affected system or apply the vendor's mitigation within your standard update timelines at low or medium mission impact and sooner than that at high, and watch the vendor's advisory for the fix.

Exploitation none (no KEV listing, exploit record or EPSS ≥ 50%) · Automatable unknown (not published for this CVE) · Technical impact partial (CVSS below 9.0). Mission impact is CISA's Mission & Well-being decision point, and only you can judge it: high means the affected system is essential to your organisation's mission, or its compromise could cause irreversible harm to people. CISA's decision table

Published

September 17, 2026

Last Modified

September 18, 2026

Advisory Details (8)

Auto-updated Sep 18, 2026
No patch confirmed yet.
generic

IB/isert: delay the final Login Response until the session is registered - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/f84e9adf4d9f4c0c79ef4a7d9e0c5c08b1337033
generic

IB/isert: delay the final Login Response until the session is registered - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/e148dbac43308d9e4313070bfc5b355d03134809
generic

IB/isert: delay the final Login Response until the session is registered - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/a6c19af05c170f267eca1d01c3c72c84ba7860ae
generic

IB/isert: delay the final Login Response until the session is registered - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/a18fb8d540b3e631cb7e50e55f3c462c05b3a114
generic

IB/isert: delay the final Login Response until the session is registered - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/464f5afa92d071a226f88424803b0fcf88093ede
generic

IB/isert: delay the final Login Response until the session is registered - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/4397ea31e3b0d017c2b9b876b326df0b3eb845bf
generic

IB/isert: delay the final Login Response until the session is registered - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/11694889c4bab47047a60690ceb70d7551ed5b2e
generic

IB/isert: delay the final Login Response until the session is registered - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/0d2efc355982064855f24f73f9fbb6c65ca4a5c7

Vendor Advisories for CVE-2026-90294(1)

These vendors published their own advisory mentioning this CVE — often with vendor-specific remediation steps + affected product lists not in NVD.

Affected Packages

(4 across 3 ecosystems)
Debian:12(2)
PackageVulnerable rangeFix by version rangeDependents
linux6.1.106-1 ... 7.2~rc7-1~exp1 (360 versions)
  • every version on: no fix on record
—
linux-6.126.12.100-1~deb12u1, 6.12.101-1~deb12u1, 6.12.107-1~deb12u1
  • every version up to 6.12.111-1~deb12u1: fixed in 6.12.111-1~deb12u1
—
Debian:13(1)
PackageVulnerable rangeFix by version rangeDependents
linux6.12.100-1 ... 6.12.96-1 (35 versions)
  • every version up to 6.12.111-1: fixed in 6.12.111-1
—
Debian:14(1)
PackageVulnerable rangeFix by version rangeDependents
linux6.12.100-1 ... 7.2~rc7-1~exp1 (179 versions)
  • every version up to 7.2.6-1: fixed in 7.2.6-1
—

Data Freshness Timeline

(refreshed 23× in last 7d / 67× in last 30d)

Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.

  1. 2026-10-05 09:13 UTCEG score recompute
  2. 2026-10-05 09:13 UTCGHSA enrichment
  3. 2026-10-04 23:22 UTCEPSS rescore
  4. 2026-10-04 20:24 UTCGHSA enrichment
  5. 2026-10-04 07:34 UTCGHSA enrichment
  6. 2026-10-03 18:49 UTCEG score recompute
  7. 2026-10-03 18:49 UTCGHSA enrichment
  8. 2026-10-03 05:14 UTCEG score recompute
  9. 2026-10-03 05:14 UTCGHSA enrichment
  10. 2026-10-02 16:29 UTCGHSA enrichment
  11. 2026-10-02 03:44 UTCEG score recompute
  12. 2026-10-02 03:44 UTCGHSA enrichment
  13. 2026-10-01 19:51 UTCEPSS rescore
  14. 2026-10-01 14:58 UTCGHSA enrichment
  15. 2026-10-01 02:13 UTCEG score recompute
  16. 2026-10-01 02:13 UTCGHSA enrichment
  17. 2026-09-30 15:04 UTCEPSS rescore
  18. 2026-09-30 13:28 UTCGHSA enrichment
  19. 2026-09-30 00:44 UTCEG score recompute
  20. 2026-09-30 00:43 UTCGHSA enrichment
  21. 2026-09-29 09:41 UTCEG score recompute
  22. 2026-09-29 09:41 UTCGHSA enrichment
  23. 2026-09-28 20:51 UTCGHSA enrichment
  24. 2026-09-28 08:05 UTCGHSA enrichment
  25. 2026-09-27 19:19 UTCEG score recompute
Show 42 more
  1. 2026-09-27 19:19 UTCGHSA enrichment
  2. 2026-09-27 13:49 UTCEPSS rescore
  3. 2026-09-27 06:34 UTCGHSA enrichment
  4. 2026-09-26 17:49 UTCEG score recompute
  5. 2026-09-26 17:49 UTCGHSA enrichment
  6. 2026-09-26 15:59 UTCEPSS rescore
  7. 2026-09-26 05:02 UTCEG score recompute
  8. 2026-09-26 05:02 UTCGHSA enrichment
  9. 2026-09-25 16:16 UTCGHSA enrichment
  10. 2026-09-25 03:30 UTCGHSA enrichment
  11. 2026-09-24 14:45 UTCEG score recompute
  12. 2026-09-24 14:45 UTCGHSA enrichment
  13. 2026-09-24 14:04 UTCEPSS rescore
  14. 2026-09-24 02:00 UTCEG score recompute
  15. 2026-09-24 02:00 UTCGHSA enrichment
  16. 2026-09-23 17:54 UTCEPSS rescore
  17. 2026-09-23 13:16 UTCGHSA enrichment
  18. 2026-09-23 00:31 UTCEG score recompute
  19. 2026-09-23 00:31 UTCGHSA enrichment
  20. 2026-09-22 16:01 UTCEPSS rescore
  21. 2026-09-22 11:46 UTCGHSA enrichment
  22. 2026-09-21 23:01 UTCEG score recompute
  23. 2026-09-21 23:01 UTCGHSA enrichment
  24. 2026-09-21 21:09 UTCEPSS rescore
  25. 2026-09-21 10:16 UTCGHSA enrichment
  26. 2026-09-20 21:32 UTCEG score recompute
  27. 2026-09-20 21:32 UTCGHSA enrichment
  28. 2026-09-20 20:16 UTCEPSS rescore
  29. 2026-09-20 08:46 UTCGHSA enrichment
  30. 2026-09-19 20:00 UTCEG score recompute
  31. 2026-09-19 20:00 UTCGHSA enrichment
  32. 2026-09-19 07:15 UTCEG score recompute
  33. 2026-09-19 07:15 UTCGHSA enrichment
  34. 2026-09-18 19:28 UTCEPSS rescore
  35. 2026-09-18 18:30 UTCEG score recompute
  36. 2026-09-18 18:30 UTCGHSA enrichment
  37. 2026-09-18 18:03 UTCEG score recompute▲ 7.50
  38. 2026-09-18 18:03 UTCGHSA enrichment
  39. 2026-09-18 17:59 UTCMITRE cvelistV5CVSS v3 → 7.5 · severity → HIGH
  40. 2026-09-17 17:24 UTCNVD update
  41. 2026-09-17 16:32 UTCEG score recompute
  42. 2026-09-17 16:19 UTCMITRE cvelistV5first tracked

Frequently asked(5)

What is CVE-2026-90294?
CVE-2026-90294 is a high vulnerability published on September 17, 2026. In the Linux kernel, the following vulnerability has been resolved: IB/isert: delay the final Login Response until the session is registered isertputlogin_tx() puts the final Login Response on the wire before transportregistersession(), which iscsipostlogin_handler() reaches only after…
When was CVE-2026-90294 disclosed?
CVE-2026-90294 was first published on September 17, 2026, with the most recent update on September 18, 2026. EchelonGraph re-ingests CVE updates from NVD on a 2-hour cycle, so this page reflects the latest published state.
Is CVE-2026-90294 actively exploited?
CVE-2026-90294 is not currently on CISA's Known Exploited Vulnerabilities catalog. FIRST EPSS estimates a 0.7% probability of exploitation in the next 30 days (52nd percentile of EPSS-scored CVEs).
What is the CVSS score of CVE-2026-90294?
CVE-2026-90294 has a CVSS base score of 7.5 (a secondary CVSS source that NVD displays; NVD's own analysis pending).
How do I remediate CVE-2026-90294?
No fix for CVE-2026-90294 is confirmed yet. Until one is published, restrict network exposure of the affected system or apply the vendor's mitigation — for example, keep it off the internet or limit it to trusted networks — and watch the vendor's advisory for the fix. The vendor advisories EchelonGraph has for CVE-2026-90294 are linked in the Vendor Advisories panel on this page.

Dependency Blast Radius

See which npm, PyPI, Go, and Maven packages are affected by CVE-2026-90294

Explore →

Is Your Infrastructure Affected by CVE-2026-90294?

EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.