A flaw was found in open-iscsi. An integer underflow vulnerability in the `iscsiuio` component, specifically during IPv4 Dynamic Host Configuration Protocol (DHCP) parsing, allows a remote attacker on the same local network segment to cause a denial of service. By sending a specially crafted IPv4/UDP DHCP reply, the attacker can trigger an out-of-bounds read, leading to the `iscsiuio` process crashing. This issue affects systems where `iscsiuio` is actively handling IPv4 DHCP traffic.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux_2023 | — | Upgrade python3-iscsi-initiator-utils-debuginfoUpgrade iscsi-initiator-utils-iscsiuioUpgrade python3-iscsi-initiator-utilsUpgrade iscsi-initiator-utils-debuginfoUpgrade iscsi-initiator-utils-debugsourceUpgrade iscsi-initiator-utils-develUpgrade iscsi-initiator-utils-iscsiuio-debuginfoUpgrade iscsi-initiator-utils | Sep 1, 2026 | Aug 13, 2026 |
| Redhat_linux | — | No solution exists | Aug 17, 2026 | Aug 12, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub