Security Advisory

CVE-2026-18728

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-13 03:13:55
Last updated 2026-08-18 14:37:36
Assigner redhat
CVSS score 6.5
State PUBLISHED

Description

A flaw was found in open-iscsi. An integer underflow vulnerability in the `iscsiuio` component, specifically during IPv4 Dynamic Host Configuration Protocol (DHCP) parsing, allows a remote attacker on the same local network segment to cause a denial of service. By sending a specially crafted IPv4/UDP DHCP reply, the attacker can trigger an out-of-bounds read, leading to the `iscsiuio` process crashing. This issue affects systems where `iscsiuio` is actively handling IPv4 DHCP traffic.