CVE-2026-63888 comprises two memory-safety defects in iscsit_handle_text_cmd(), the Linux kernel LIO iSCSI target Text PDU handler. When DataDigest=CRC32C is negotiated, the handler passes a receive length that includes the four-byte digest to iscsit_crc_buf(), although the text buffer allocation contains only the padded payload. CRC calculation consequently reads four bytes beyond the allocation. Separately, a DataDigest mismatch with ErrorRecoveryLevel greater than zero frees the text buffer without clearing cmd->text_in_ptr. A subsequent Text Request using the same Initiator Task Tag (ITT), or session teardown, frees the stale pointer again. Both defects date to the original LIO iSCSI integration. The double-free can cause a remote kernel BUG on hardened kernels or slab freelist corruption on non-hardened kernels.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
83 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
CRC overread and double-free vulnerability in the Linux kernel's iSCSI target implementation. The advisory provides a live patch for the affected SUSE kernel. This CVE is the source of the plugin's CVSS v3 score of 9.8; its temporal vector indicates proof-of-concept exploit availability. Nessus checks the reported package version rather than testing exploitation.
CRC overread and double-free vulnerability in the Linux kernel iSCSI target implementation. The plugin attributes a critical CVSS v3 score of 9.8 to this CVE, with a temporal vector indicating proof-of-concept exploit maturity. SUSE addresses it in Live Patch 84 for SUSE Linux Enterprise 12 SP5.
CRC overread and double-free vulnerability in the Linux kernel's iSCSI target command handler. It is fixed by the SUSE kernel live-patch update. The CVSS v3 metadata associated with this CVE indicates proof-of-concept exploit maturity and a base score of 9.8.
CRC overread and double-free issues in the Linux kernel iSCSI target function iscsit_handle_text_cmd(), fixed by the referenced SUSE kernel live patch update.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.