Skip to content
Red HatCVE-2026-18728

Red Hat open-iscsi. An integer underflow vulnerability: integer overflow

Medium6.5CVE-2026-18728 · Published Aug 13, 2026 · updated Aug 25, 2026

A flaw was found in open-iscsi. An integer underflow vulnerability in the `iscsiuio` component, specifically during IPv4 Dynamic Host Configuration Protocol (DHCP) parsing, allows a remote attacker on the same local network segment to cause a denial of service. By sending a specially crafted IPv4/UDP DHCP reply, the attacker can trigger an out-of-bounds read, leading to the `iscsiuio` process crashing. This issue affects systems where `iscsiuio` is actively handling IPv4 DHCP traffic.

Red Hat advisory

Affected versions

PackageAffectedFixed in
Red Hat Enterprise Linux 10
Product
all versionsNo fix yet
Red Hat Enterprise Linux 9
Product
all versionsNo fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-191

More Red Hat advisories

All Red Hat
Advisory
Red Hat Ansible Automation Platform 2: incomplete cleanup
Medium4.2Aug 13
A flaw was found in the clusterclaims-controller component of Multicluster...
High7.1Aug 13
Red Hat sblim-sfcb: unsafe deserialization
Medium6.6Aug 13
Red Hat sblim-sfcb. A local: race condition
Medium6.3Aug 13
A flaw was found in sblim-cmpi-base
Medium6.3Aug 13
Red Hat: mass assignment
High8.5Aug 12

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.