Linux Kernel NULL Pointer Dereference Vulnerability in iSCSI Target Module

Vulnerability

A vulnerability in the Linux kernel's SCSI target iSCSI module can lead to a NULL pointer dereference, causing a kernel crash. This issue arises when the NOPIN response timer expires on a deleted connection, leading to a failure in the connection handling. The problem occurs because the NOPIN response timer may be restarted after it has expired, without properly stopping the timer first, which can create a race condition.

Impact

Exploitation of this vulnerability causes a kernel crash due to a NULL pointer dereference, disrupting system operations and potentially leading to a denial of service.

Added: Jun 18, 2025, 10:31 AM
Updated: Jun 18, 2025, 10:31 AM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
2.5
exploitability
5.3
remediation
0.0
relevance
0.2
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.