CVE-2026-18728
EUVD-2026-5771513.08.2026, 04:17
A flaw was found in open-iscsi. An integer underflow vulnerability in the `iscsiuio` component, specifically during IPv4 Dynamic Host Configuration Protocol (DHCP) parsing, allows a remote attacker on the same local network segment to cause a denial of service. By sending a specially crafted IPv4/UDP DHCP reply, the attacker can trigger an out-of-bounds read, leading to the `iscsiuio` process crashing. This issue affects systems where `iscsiuio` is actively handling IPv4 DHCP traffic.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| redhat | enterprise_linux | 9.0 |
| redhat | enterprise_linux | 10.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Amazon Linux Releases
Amazon Package | |||||
|---|---|---|---|---|---|
| iscsi-initiator-utils |
| ||||
| iscsi-initiator-utils-debuginfo |
| ||||
| iscsi-initiator-utils-debugsource |
| ||||
| iscsi-initiator-utils-devel |
| ||||
| iscsi-initiator-utils-iscsiuio |
| ||||
| iscsi-initiator-utils-iscsiuio-debuginfo |
| ||||
| python3-iscsi-initiator-utils |
| ||||
| python3-iscsi-initiator-utils-debuginfo |
|
Common Weakness Enumeration