Linux Kernel iSCSI Boot IPv6 Subnet Mask Shift-Out-Of-Bounds Vulnerability

Vulnerability

A vulnerability in the Linux kernel's iSCSI boot process over IPv6 has been identified. The issue arises because 'iscsistart' reads the subnet mask entry from the iBFT firmware, which is not applicable to IPv6. This discrepancy causes a shift-out-of-bounds error, triggering a UBSAN warning. The vulnerability affects several Linux kernel versions.

Impact

Exploitation of this vulnerability causes a shift-out-of-bounds error, which can lead to undefined behavior in the program, potentially allowing for memory corruption or other unintended consequences.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
0.0
exploitability
5.3
remediation
0.0
relevance
0.0
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.