CVE-2026-18726
EUVD-2026-5763612.08.2026, 22:17
A flaw was found in open-iscsi. This vulnerability allows a remote attacker on the same local network segment to cause a Denial of Service (DoS) in the iscsiuio daemon. By sending a specially crafted Internet Control Message Protocol version 6 (ICMPv6) Router Advertisement with a zero-length option, the attacker can trigger an infinite loop. This leads to sustained CPU usage, rendering the daemon unresponsive and impacting system availability. A secondary risk of out-of-bounds reads exists with a short IPv6 payload, though no memory corruption or data exposure has been confirmed.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| redhat | enterprise_linux | 9.0 |
| redhat | enterprise_linux | 10.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Amazon Linux Releases
Amazon Package | |||||
|---|---|---|---|---|---|
| iscsi-initiator-utils |
| ||||
| iscsi-initiator-utils-debuginfo |
| ||||
| iscsi-initiator-utils-debugsource |
| ||||
| iscsi-initiator-utils-devel |
| ||||
| iscsi-initiator-utils-iscsiuio |
| ||||
| iscsi-initiator-utils-iscsiuio-debuginfo |
| ||||
| python3-iscsi-initiator-utils |
| ||||
| python3-iscsi-initiator-utils-debuginfo |
|
Common Weakness Enumeration