Integer Underflow Vulnerability in open-iscsi Affects Red Hat Systems
CVE-2026-18728
6.5MEDIUM
What is CVE-2026-18728?
A significant flaw has been identified in the open-iscsi utility, where an integer underflow occurs within the iscsiuio component during the processing of IPv4 DHCP replies. This vulnerability allows attackers on the same local network segment to send tailored IPv4/UDP DHCP responses that can exploit this weakness. As a result, the iscsiuio process can experience an out-of-bounds read, potentially leading to a denial of service. Systems utilizing iscsiuio to handle IPv4 DHCP operations are particularly at risk.
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Keith Linneman (Linneman Labs) for reporting this issue.