Bug 2439887 (CVE-2026-23193) - CVE-2026-23193 kernel: scsi: target: iscsi: Fix use-after-free in iscsit_dec_session_usage_count()
Summary: CVE-2026-23193 kernel: scsi: target: iscsi: Fix use-after-free in iscsit_dec_...
Keywords:
Status: NEW
Alias: CVE-2026-23193
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-02-14 17:01 UTC by OSIDB Bzimport
Modified: 2026-05-06 18:45 UTC (History)
0 users

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2026:10108 0 None None None 2026-04-23 22:46:43 UTC
Red Hat Product Errata RHSA-2026:10756 0 None None None 2026-04-27 10:31:47 UTC
Red Hat Product Errata RHSA-2026:13664 0 None None None 2026-05-05 09:29:24 UTC
Red Hat Product Errata RHSA-2026:13681 0 None None None 2026-05-05 10:15:32 UTC
Red Hat Product Errata RHSA-2026:13734 0 None None None 2026-05-05 13:05:46 UTC
Red Hat Product Errata RHSA-2026:13936 0 None None None 2026-05-06 08:15:37 UTC
Red Hat Product Errata RHSA-2026:14137 0 None None None 2026-05-06 13:38:07 UTC
Red Hat Product Errata RHSA-2026:14165 0 None None None 2026-05-06 14:11:26 UTC
Red Hat Product Errata RHSA-2026:14301 0 None None None 2026-05-06 18:45:43 UTC
Red Hat Product Errata RHSA-2026:6153 0 None None None 2026-03-30 11:06:28 UTC
Red Hat Product Errata RHSA-2026:6571 0 None None None 2026-04-06 01:44:45 UTC
Red Hat Product Errata RHSA-2026:6572 0 None None None 2026-04-06 01:31:24 UTC
Red Hat Product Errata RHSA-2026:6632 0 None None None 2026-04-06 07:50:01 UTC
Red Hat Product Errata RHSA-2026:9095 0 None None None 2026-04-20 18:11:48 UTC
Red Hat Product Errata RHSA-2026:9112 0 None None None 2026-04-20 20:28:58 UTC
Red Hat Product Errata RHSA-2026:9870 0 None None None 2026-04-22 20:40:49 UTC

Description OSIDB Bzimport 2026-02-14 17:01:32 UTC
In the Linux kernel, the following vulnerability has been resolved:

scsi: target: iscsi: Fix use-after-free in iscsit_dec_session_usage_count()

In iscsit_dec_session_usage_count(), the function calls complete() while
holding the sess->session_usage_lock. Similar to the connection usage count
logic, the waiter signaled by complete() (e.g., in the session release
path) may wake up and free the iscsit_session structure immediately.

This creates a race condition where the current thread may attempt to
execute spin_unlock_bh() on a session structure that has already been
deallocated, resulting in a KASAN slab-use-after-free.

To resolve this, release the session_usage_lock before calling complete()
to ensure all dereferences of the sess pointer are finished before the
waiter is allowed to proceed with deallocation.

Comment 5 errata-xmlrpc 2026-03-30 11:06:27 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:6153 https://access.redhat.com/errata/RHSA-2026:6153

Comment 6 errata-xmlrpc 2026-04-06 01:31:23 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:6572 https://access.redhat.com/errata/RHSA-2026:6572

Comment 7 errata-xmlrpc 2026-04-06 01:44:44 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:6571 https://access.redhat.com/errata/RHSA-2026:6571

Comment 8 errata-xmlrpc 2026-04-06 07:50:00 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:6632 https://access.redhat.com/errata/RHSA-2026:6632

Comment 9 errata-xmlrpc 2026-04-20 18:11:47 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10.0 Extended Update Support

Via RHSA-2026:9095 https://access.redhat.com/errata/RHSA-2026:9095

Comment 10 errata-xmlrpc 2026-04-20 20:28:57 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2026:9112 https://access.redhat.com/errata/RHSA-2026:9112

Comment 11 errata-xmlrpc 2026-04-22 20:40:48 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7 Extended Lifecycle Support

Via RHSA-2026:9870 https://access.redhat.com/errata/RHSA-2026:9870

Comment 12 errata-xmlrpc 2026-04-23 22:46:42 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Extended Update Support

Via RHSA-2026:10108 https://access.redhat.com/errata/RHSA-2026:10108

Comment 14 errata-xmlrpc 2026-04-27 10:31:45 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7 Extended Lifecycle Support

Via RHSA-2026:10756 https://access.redhat.com/errata/RHSA-2026:10756

Comment 15 errata-xmlrpc 2026-05-05 09:29:23 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.6 Telecommunications Update Service

Via RHSA-2026:13664 https://access.redhat.com/errata/RHSA-2026:13664

Comment 16 errata-xmlrpc 2026-05-05 10:15:31 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.8 Telecommunications Update Service

Via RHSA-2026:13681 https://access.redhat.com/errata/RHSA-2026:13681

Comment 17 errata-xmlrpc 2026-05-05 13:05:43 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

Via RHSA-2026:13734 https://access.redhat.com/errata/RHSA-2026:13734

Comment 18 errata-xmlrpc 2026-05-06 08:15:36 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions

Via RHSA-2026:13936 https://access.redhat.com/errata/RHSA-2026:13936

Comment 19 errata-xmlrpc 2026-05-06 13:38:06 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions

Via RHSA-2026:14137 https://access.redhat.com/errata/RHSA-2026:14137

Comment 20 errata-xmlrpc 2026-05-06 14:11:25 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On

Via RHSA-2026:14165 https://access.redhat.com/errata/RHSA-2026:14165

Comment 21 errata-xmlrpc 2026-05-06 18:45:42 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

Via RHSA-2026:14301 https://access.redhat.com/errata/RHSA-2026:14301


Note You need to log in before you can comment on or make changes to this bug.