CVE-2026-18727

NameCVE-2026-18727
DescriptionA flaw was found in open-iscsi's iscsiuio component. This vulnerability involves an integer underflow and out-of-bounds read during Dynamic Host Configuration Protocol for IPv6 (DHCPv6) packet parsing. Specifically, crafted DHCPv6 Advertise traffic with a short User Datagram Protocol (UDP) length can cause the DHCPv6 payload length to underflow. An unauthenticated attacker on an adjacent network segment can exploit this by sending specially crafted IPv6 UDP traffic while the client is in an active DHCPv6 exchange, leading to a denial of service due to a process crash or service disruption.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1144935

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
open-iscsi (PTS)bookworm2.1.8-1vulnerable
trixie2.1.11-1+deb13u2vulnerable
forky, sid2.1.12-2vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
open-iscsisource(unstable)(unfixed)1144935

Notes

[trixie] - open-iscsi <no-dsa> (Minor issue)
https://bugzilla.redhat.com/show_bug.cgi?id=2462956
https://github.com/open-iscsi/open-iscsi/issues/543
https://github.com/open-iscsi/open-iscsi/pull/544
Fixed by: https://github.com/open-iscsi/open-iscsi/commit/0bdc1ab6718215e67a4acff1e711fc8c6693cff4

Search for package or bug name: Reporting problems