#1144935 open-iscsi: CVE-2026-18724 CVE-2026-18725 CVE-2026-18726 CVE-2026-18727 CVE-2026-18728

Package:
src:open-iscsi
Source:
src:open-iscsi
Submitter:
Salvatore Bonaccorso
Date:
2026-09-09 08:21:02 UTC
Severity:
normal
Tags:
#1144935#5
Date:
2026-08-20 15:49:09 UTC
From:
To:
Hi,

The following vulnerabilities were published for open-iscsi.

CVE-2026-18724[0]:
| idbm: fix stack buffer overflow in idbm_recinfo_config()


CVE-2026-18725[1]:
| iscsiuio: fix out-of-bounds access in IPv6 ICMPv6 echo handling


CVE-2026-18726[2]:
| A flaw was found in open-iscsi. This vulnerability allows a remote
| attacker on the same local network segment to cause a Denial of
| Service (DoS) in the iscsiuio daemon. By sending a specially crafted
| Internet Control Message Protocol version 6 (ICMPv6) Router
| Advertisement with a zero-length option, the attacker can trigger an
| infinite loop. This leads to sustained CPU usage, rendering the
| daemon unresponsive and impacting system availability. A secondary
| risk of out-of-bounds reads exists with a short IPv6 payload, though
| no memory corruption or data exposure has been confirmed.


CVE-2026-18727[3]:
| A flaw was found in open-iscsi's iscsiuio component. This
| vulnerability involves an integer underflow and out-of-bounds read
| during Dynamic Host Configuration Protocol for IPv6 (DHCPv6) packet
| parsing. Specifically, crafted DHCPv6 Advertise traffic with a short
| User Datagram Protocol (UDP) length can cause the DHCPv6 payload
| length to underflow. An unauthenticated attacker on an adjacent
| network segment can exploit this by sending specially crafted IPv6
| UDP traffic while the client is in an active DHCPv6 exchange,
| leading to a denial of service due to a process crash or service
| disruption.


CVE-2026-18728[4]:
| A flaw was found in open-iscsi. An integer underflow vulnerability
| in the `iscsiuio` component, specifically during IPv4 Dynamic Host
| Configuration Protocol (DHCP) parsing, allows a remote attacker on
| the same local network segment to cause a denial of service. By
| sending a specially crafted IPv4/UDP DHCP reply, the attacker can
| trigger an out-of-bounds read, leading to the `iscsiuio` process
| crashing. This issue affects systems where `iscsiuio` is actively
| handling IPv4 DHCP traffic.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-18724
https://www.cve.org/CVERecord?id=CVE-2026-18724
[1] https://security-tracker.debian.org/tracker/CVE-2026-18725
https://www.cve.org/CVERecord?id=CVE-2026-18725
[2] https://security-tracker.debian.org/tracker/CVE-2026-18726
https://www.cve.org/CVERecord?id=CVE-2026-18726
[3] https://security-tracker.debian.org/tracker/CVE-2026-18727
https://www.cve.org/CVERecord?id=CVE-2026-18727
[4] https://security-tracker.debian.org/tracker/CVE-2026-18728
https://www.cve.org/CVERecord?id=CVE-2026-18728

Regards,
Salvatore

#1144935#12
Date:
2026-09-09 08:19:40 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
open-iscsi, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1144935@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Chris Hofstaedtler <zeha@debian.org> (supplier of updated open-iscsi package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Wed, 09 Sep 2026 10:05:14 +0200
Source: open-iscsi
Architecture: source
Version: 2.1.13-1
Distribution: unstable
Urgency: medium
Maintainer: Debian iSCSI Maintainers <open-iscsi@packages.debian.org>
Changed-By: Chris Hofstaedtler <zeha@debian.org>
Closes: 1144935
Changes:
 open-iscsi (2.1.13-1) unstable; urgency=medium
 .
   * New upstream release, fixes  CVE-2026-18724, CVE-2026-18725,
     CVE-2026-18726, CVE-2026-18727, CVE-2026-18728 (Closes: #1144935)
 .
   [ Chris Hofstaedtler ]
   * [235bfe0] debian scripts: stop hardcoding initiator name prefix
   * [f94e354] debian scripts: drop GenerateName=yes remnants
Checksums-Sha1:
 1576c98dc56b3f580eb2af7d703cf9968a95d2d9 2479 open-iscsi_2.1.13-1.dsc
 7b4ec6dc14867b00f4041f283c6bdacb32ca4d07 649462 open-iscsi_2.1.13.orig.tar.gz
 489af6bca825fc749b4c1ea0d38a3551cf944a63 63388 open-iscsi_2.1.13-1.debian.tar.xz
 d04854c26637e55e936828d822f7c010d833100a 8962 open-iscsi_2.1.13-1_arm64.buildinfo
Checksums-Sha256:
 aa7e9ce56bf69547b4e69582ad5a910709a01c462f8f38036c53eea59a2cf4b9 2479 open-iscsi_2.1.13-1.dsc
 2b06968d7d744ac4d13c20f5b6420f550c05e0ad1e097aaef55bb30e877a6a24 649462 open-iscsi_2.1.13.orig.tar.gz
 e8695dac1293a63d0b8c845fc909005cb2098a5af0b2e388961240ce9a765a22 63388 open-iscsi_2.1.13-1.debian.tar.xz
 a4249e0d57254224db0f1b454f35f748cda653b924d3ebf7e38263a2a73a8ece 8962 open-iscsi_2.1.13-1_arm64.buildinfo
Files:
 052b5c2ca750d53e770f08082d817956 2479 net optional open-iscsi_2.1.13-1.dsc
 298e03c90571a76655307fbcbd09f215 649462 net optional open-iscsi_2.1.13.orig.tar.gz
 1d0bbd178ee96f21062b941525c225e1 63388 net optional open-iscsi_2.1.13-1.debian.tar.xz
 e13732c74c364082ccb13805fb433e14 8962 net optional open-iscsi_2.1.13-1_arm64.buildinfo
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEfRrP+tnggGycTNOSXBPW25MFLgMFAmqhFCAACgkQXBPW25MF
LgPvOhAAm6fjMbacFii2Re8LPtyKOUkbZN8p7vuzfoetrTFwUxuEQtiSQehq8FeH
PNwFgfh6AWKGLyXbnR8BwNDh/xtVsUdTS7Z3JF5ve847BnG8115xFnOL7a+fDc1Q
DZfFz4nkT5dvmdELgRMej/AmZcChUkBjZ1FMgAIpq4DwcqjC8CMHZ3lYfKciG2EE
NUWb1+KxeMeoOOU79Ay9IWvPHfcZrcax62IlS5BpxuwdVdprQbAv8A17wP1OBHtN
dM6DO99Lqalot3iPXMu+woVkqlTeruu43aU/4vN3uTV/Kas3kvVrC/phKp19uCD0
TxngKlTlYztlkmMpLjgYP+xlf3rUmHEfKFRJtC/T93TyZX6cZelfhzTzVIkGoZoS
mbUmkUKs34QNue/np019dj/loxH0B0sB4swlO6wnuJRm/pXlCLSU5a/iZYlz5gbY
WAiHo1pSKcrcRAFtrdc3KMLdsYvcu/fYiUnrUu7M/S3z7ZLM+lzG1oekXSTLecJp
LH1Yf3wrCc0TUGYQHwP2+cYZkqffir8ReKnE7/NQuV26ARpM0/CRRiBb1+eCi/Qj
0kr3ASJdoYpRzwsv9j/SRLONzyDwO7GpcOF4S4dirVxHU1kiBT8nMgWz+y00rSS8
jAO8w2hXoI/xqyqzsGkuTm/06LTJD+UOtYvpbf5e7xk+LHyGzgg=
=JrW4
-----END PGP SIGNATURE-----