Double free vulnerability in the iscsi_rx_handler function (usr/iscsi/iscsid.c) in the tgt daemon (tgtd) in Linux SCSI target framework (tgt) before 1.0.14, aka scsi-target-utils, allows remote attackers to cause a denial of service (memory corruption and crash) and possibly execute arbitrary code via unknown vectors related to a buffer overflow during iscsi login. NOTE: some of these details are obtained from third party information.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade scsi-target-utils | Dec 1, 2016 | Mar 15, 2011 |
| Debian | — | Upgrade tgt | Jul 30, 2024 | Mar 15, 2011 |
| Oracle_linux | — | Upgrade scsi-target-utils | Oct 16, 2024 | Mar 15, 2011 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Mar 9, 2011 |
| Suse | — | Upgrade tgt | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade tgt | Nov 8, 2024 | Mar 15, 2011 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub