Hi,
The following vulnerabilities were published for open-iscsi.
CVE-2026-18724[0]:
| idbm: fix stack buffer overflow in idbm_recinfo_config()
CVE-2026-18725[1]:
| iscsiuio: fix out-of-bounds access in IPv6 ICMPv6 echo handling
CVE-2026-18726[2]:
| A flaw was found in open-iscsi. This vulnerability allows a remote
| attacker on the same local network segment to cause a Denial of
| Service (DoS) in the iscsiuio daemon. By sending a specially crafted
| Internet Control Message Protocol version 6 (ICMPv6) Router
| Advertisement with a zero-length option, the attacker can trigger an
| infinite loop. This leads to sustained CPU usage, rendering the
| daemon unresponsive and impacting system availability. A secondary
| risk of out-of-bounds reads exists with a short IPv6 payload, though
| no memory corruption or data exposure has been confirmed.
CVE-2026-18727[3]:
| A flaw was found in open-iscsi's iscsiuio component. This
| vulnerability involves an integer underflow and out-of-bounds read
| during Dynamic Host Configuration Protocol for IPv6 (DHCPv6) packet
| parsing. Specifically, crafted DHCPv6 Advertise traffic with a short
| User Datagram Protocol (UDP) length can cause the DHCPv6 payload
| length to underflow. An unauthenticated attacker on an adjacent
| network segment can exploit this by sending specially crafted IPv6
| UDP traffic while the client is in an active DHCPv6 exchange,
| leading to a denial of service due to a process crash or service
| disruption.
CVE-2026-18728[4]:
| A flaw was found in open-iscsi. An integer underflow vulnerability
| in the `iscsiuio` component, specifically during IPv4 Dynamic Host
| Configuration Protocol (DHCP) parsing, allows a remote attacker on
| the same local network segment to cause a denial of service. By
| sending a specially crafted IPv4/UDP DHCP reply, the attacker can
| trigger an out-of-bounds read, leading to the `iscsiuio` process
| crashing. This issue affects systems where `iscsiuio` is actively
| handling IPv4 DHCP traffic.
If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-18724
https://www.cve.org/CVERecord?id=CVE-2026-18724
[1] https://security-tracker.debian.org/tracker/CVE-2026-18725
https://www.cve.org/CVERecord?id=CVE-2026-18725
[2] https://security-tracker.debian.org/tracker/CVE-2026-18726
https://www.cve.org/CVERecord?id=CVE-2026-18726
[3] https://security-tracker.debian.org/tracker/CVE-2026-18727
https://www.cve.org/CVERecord?id=CVE-2026-18727
[4] https://security-tracker.debian.org/tracker/CVE-2026-18728
https://www.cve.org/CVERecord?id=CVE-2026-18728
Regards,
Salvatore