CVE-2026-18726

A flaw was found in open-iscsi. This vulnerability allows a remote attacker on the same local network segment to cause a Denial of Service (DoS) in the iscsiuio daemon. By sending a specially crafted Internet Control Message Protocol version 6 (ICMPv6) Router Advertisement with a zero-length option, the attacker can trigger an infinite loop. This leads to sustained CPU usage, rendering the daemon unresponsive and impacting system availability. A secondary risk of out-of-bounds reads exists with a short IPv6 payload, though no memory corruption or data exposure has been confirmed.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-08-12 22:17

Updated : 2026-08-25 16:54


NVD link : CVE-2026-18726

Mitre link : CVE-2026-18726

CVE.ORG link : CVE-2026-18726


JSON object : View

Products Affected

redhat

  • enterprise_linux
CWE
CWE-835

Loop with Unreachable Exit Condition ('Infinite Loop')