Integer Underflow Vulnerability in open-iscsi's iscsiuio Component
CVE-2026-18727
6.5MEDIUM
What is CVE-2026-18727?
A vulnerability exists in open-iscsi's iscsiuio component due to an integer underflow and out-of-bounds read during DHCPv6 packet parsing. This flaw can be exploited by an unauthenticated attacker on an adjacent network segment who sends specially crafted IPv6 UDP traffic. When the client engages in an active DHCPv6 exchange, maliciously crafted DHCPv6 Advertise traffic with a short UDP length can cause the DHCPv6 payload length to underflow, leading to a denial of service through process crashes or service disruptions.
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Keith Linneman (Linneman Labs) for reporting this issue.