#1143059 open-iscsi: CVE-2026-44943 CVE-2026-44944

Package:
src:open-iscsi
Source:
src:open-iscsi
Submitter:
Salvatore Bonaccorso
Date:
2026-07-31 16:45:01 UTC
Severity:
normal
Tags:
#1143059#5
Date:
2026-07-30 04:52:30 UTC
From:
To:
Hi,

The following vulnerabilities were published for open-iscsi.

CVE-2026-44943[0]:
| An Improper Limitation of a Pathname to a Restricted Directory
| ('Path Traversal') vulnerability in open-iscsi allows remote MITM
| attackers  to create root-owned files outside the database and
| inject lines into the record.       This issue affects open-iscsi:
| from through 668ca1df9c9a1e9bdd5c999ae1d67c9c8909237e.


CVE-2026-44944[1]:
| An Incorrect Authorization vulnerability in open-iscsi
| allows unprivilidged local users to use the isscsiuio control
| socket.       This issue affects open-iscsi: from ? through
| 668ca1df9c9a1e9bdd5c999ae1d67c9c8909237e.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-44943
https://www.cve.org/CVERecord?id=CVE-2026-44943
[1] https://security-tracker.debian.org/tracker/CVE-2026-44944
https://www.cve.org/CVERecord?id=CVE-2026-44944
[2] https://github.com/open-iscsi/open-iscsi/commit/668ca1df9c9a1e9bdd5c999ae1d67c9c8909237e

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1143059#12
Date:
2026-07-31 16:42:57 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
open-iscsi, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1143059@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Chris Hofstaedtler <zeha@debian.org> (supplier of updated open-iscsi package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Fri, 31 Jul 2026 18:29:42 +0200
Source: open-iscsi
Architecture: source
Version: 2.1.12-1
Distribution: unstable
Urgency: medium
Maintainer: Debian iSCSI Maintainers <open-iscsi@packages.debian.org>
Changed-By: Chris Hofstaedtler <zeha@debian.org>
Closes: 1143059
Changes:
 open-iscsi (2.1.12-1) unstable; urgency=medium
 .
   * New upstream release, fixes CVE-2026-44943, CVE-2026-44944
     (Closes: #1143059)
   * [53f7d4d] Rebase patches
Checksums-Sha1:
 a34f70b95c221a3b83c4be5f2c2e1abeb1b6a481 2518 open-iscsi_2.1.12-1.dsc
 979c57911fe02ee85accb261aa5211f4014e8b40 646891 open-iscsi_2.1.12.orig.tar.gz
 a32a1f0710cc7795ed5c4e2887a2d2268e185d69 59568 open-iscsi_2.1.12-1.debian.tar.xz
 6a003e120f337d89137c85bb742a6b5fb60d9c59 9059 open-iscsi_2.1.12-1_arm64.buildinfo
Checksums-Sha256:
 67a54040ccadcf9a558b16f1817e57f1b86b23440ad514f74c4cf02009cd09f6 2518 open-iscsi_2.1.12-1.dsc
 7d149d5ccdea9c95dcd815efc527c78c60120b62be227c663b97286ab55bf2dd 646891 open-iscsi_2.1.12.orig.tar.gz
 3c2fb39dd6481f9fd91166140c4154c172e50e304a98ac80eac94ae7fa8e289a 59568 open-iscsi_2.1.12-1.debian.tar.xz
 aefd32fbea9e4913b10dc0c18ad9cbd247a9e5dd4fcd788c032352cd1754d365 9059 open-iscsi_2.1.12-1_arm64.buildinfo
Files:
 98eec408fec14d0656b5f2ab25382726 2518 net optional open-iscsi_2.1.12-1.dsc
 1bd844d212f95a1a3eb63e7e08d4896d 646891 net optional open-iscsi_2.1.12.orig.tar.gz
 dcec7dc37af9e28a832693ef6890c98e 59568 net optional open-iscsi_2.1.12-1.debian.tar.xz
 d5ee15092dcbec740763533c52113d3d 9059 net optional open-iscsi_2.1.12-1_arm64.buildinfo
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEfRrP+tnggGycTNOSXBPW25MFLgMFAmpszhAACgkQXBPW25MF
LgORPA//Uu23xTwy8NYYe8WPeuhjxYw7bAY7KFKT2LYXNvUDVFjcK8GraVp6rypc
/kPzU2XqjX4PQrFbS90KUfeXK7FHZW+I/vfBmmmqlT1RZuGikHK3WwZSS/EQ1uAa
YEBUmuecZGzezucGT+VrxwAC7T0cBs4Vpi/AXkyu/0uRg15PpBNE6X57QhhxBSNC
GnTopHMOptObonjkLxJ3K09kaWL7IV4RIdQxB5ftuV3itbKyVqflC1KCZEEg97+2
yxOLZtDETJAUFumlui9xMUamPpNYdQGOFWZeKvl62jgUCoasyEkX6w6s1F4WAQPQ
s/ukr9y5md7FmQKGTDWoGo7mPdcL512kXa8MGHNkbPrll3ZZBnutNcVvkzXQwP8c
Il+8YUm2xNTWIS/05kkLi2Jy2aTPsIYhuVMI+0B8G1kEV3tN0cErUyqXy4SSTyVM
QLmn4SE2mhZypxv34iP+LtrbvkocrZOjQzttcJoaS8QGVuaw9nDEVNkYWPn82MvR
R+Y3qgQzNDb+LFPHWmE0hGKSylIaV7HohO5W0RXPwHqMFqtqteagUOvkc9nr2Yv4
6i7eodn3OhRLhOk/N/c8BeBh8QM9ZlrN/mHqYrpN9DGjIjo3OMxlMGTQ5L6W1COb
DCN5tw+b5h7RvyujtDFVDo5RagmZRHM58pRsCFSjxl2A3oKwQts=
=Duzs
-----END PGP SIGNATURE-----