Integer Underflow Vulnerability in open-iscsi Affects Red Hat Systems
CVE-2026-18728

6.5MEDIUM

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
13 August 2026

What is CVE-2026-18728?

A significant flaw has been identified in the open-iscsi utility, where an integer underflow occurs within the iscsiuio component during the processing of IPv4 DHCP replies. This vulnerability allows attackers on the same local network segment to send tailored IPv4/UDP DHCP responses that can exploit this weakness. As a result, the iscsiuio process can experience an out-of-bounds read, potentially leading to a denial of service. Systems utilizing iscsiuio to handle IPv4 DHCP operations are particularly at risk.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Keith Linneman (Linneman Labs) for reporting this issue.
.