← All Advisories

CVE-2026-97951

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-97951

Key Details

CVECVE-2026-97951
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

scsi: target: iscsi: Fix hang for aborted WRITE_PENDING commands

When a LUN_RESET aborts a WRITE command that is in the

TRANSPORT_WRITE_PENDING state, the target core sets CMD_T_ABORTED and

waits for the frontend to finish processing.

If the initiator subsequently sends the remaining dataout PDUs,

__iscsit_check_dataout_hdr() catches the payload, stops the dataout

timer if the sequence is final and finally dumps the data. However, the

iSCSI target doesn't trigger the completion process for these aborted

commands. Because of this, the abort path hangs indefinitely in

target_put_cmd_and_wait(), leading to a deadlocked target worker thread.

Fix this by explicitly calling target_complete_cmd() when the final

dataout PDU is received for an aborted WRITE command.

target_complete_cmd() detects the CMD_T_ABORTED flag and cleanly routes

the command into target_abort_work, allowing the abort completion to

successfully unblock. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-97951
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-97951