CVE-2026-63886 is a heap-based buffer overflow in the Linux kernel's SCSI target iSCSI authentication code during CHAP processing. In the vulnerable path, chap_server_compute_hash() allocates a digest buffer sized to chap->digest_size and, for BASE64-encoded CHAP responses, passes the attacker-controlled CHAP_R value to chap_base64_decode() without first validating whether the encoded input can decode to more bytes than the allocated digest buffer can hold. Because the decoder writes output as long as input remains, an oversized BASE64 response can overflow the heap buffer before a later length check is reached. With the documented bounds, up to 127 BASE64 characters may reach the decoder, which can decode to 95 bytes, exceeding the expected digest buffer size for algorithms such as SHA-256 or MD5. The flaw affects the iSCSI target login path prior to successful authentication. The fix adds an upfront validation step for the BASE64 branch by stripping trailing padding characters and rejecting inputs whose effective encoded length exceeds the maximum valid size for the configured digest before decoding.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.