A flaw was found in open-iscsi. This vulnerability allows a remote attacker on the same local network segment to cause a Denial of Service (DoS) in the iscsiuio daemon. By sending a specially crafted Internet Control Message Protocol version 6 (ICMPv6) Router Advertisement with a zero-length option, the attacker can trigger an infinite loop. This leads to sustained CPU usage, rendering the daemon unresponsive and impacting system availability. A secondary risk of out-of-bounds reads exists with a short IPv6 payload, though no memory corruption or data exposure has been confirmed.
References
| Link | Resource |
|---|---|
| https://access.redhat.com/security/cve/CVE-2026-18726 | Vendor Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2462331 | Issue Tracking |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-08-12 22:17
Updated : 2026-08-25 16:54
NVD link : CVE-2026-18726
Mitre link : CVE-2026-18726
CVE.ORG link : CVE-2026-18726
JSON object : View
Products Affected
redhat
- enterprise_linux
CWE
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
