Back

MEDIUM

Open-iscsi: open-iscsi: integer underflow in iscsiuio ipv4 dhcp parsing

Published Aug 13, 2026

Description

A flaw was found in open-iscsi. An integer underflow vulnerability in the `iscsiuio` component, specifically during IPv4 Dynamic Host Configuration Protocol (DHCP) parsing, allows a remote attacker on the same local network segment to cause a denial of service. By sending a specially crafted IPv4/UDP DHCP reply, the attacker can trigger an out-of-bounds read, leading to the `iscsiuio` process crashing. This issue affects systems where `iscsiuio` is actively handling IPv4 DHCP traffic.

Affected products

Remediation

Vendor solution

To mitigate this issue, restrict network access to `iscsiuio`-managed interfaces. Configure firewall rules to limit DHCP/BOOTP traffic to only trusted infrastructure within the local broadcast domain. This reduces the exposure to untrusted systems that could send crafted IPv4 DHCP packets. If `iscsiuio` is actively using IPv4 DHCP, consider reconfiguring it to use static IP addresses or a different network configuration if feasible. Changes to network configuration may require a service restart.

Red Hat statement

This flaw in `iscsi-initiator-utils` is rated Moderate. It allows an adjacent-network attacker to trigger a denial of service by sending a crafted IPv4/UDP DHCP reply to systems where `iscsiuio` is configured to use IPv4 DHCP. Exploitation requires specific network conditions and a vulnerable configuration, limiting its broader impact.

Red Hat mitigation

To mitigate this issue, restrict network access to `iscsiuio`-managed interfaces. Configure firewall rules to limit DHCP/BOOTP traffic to only trusted infrastructure within the local broadcast domain. This reduces the exposure to untrusted systems that could send crafted IPv4 DHCP packets. If `iscsiuio` is actively using IPv4 DHCP, consider reconfiguring it to use static IP addresses or a different network configuration if feasible. Changes to network configuration may require a service restart.

Metrics

Weaknesses (1)

References (4)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Aug 13, 2026
Updated Aug 18, 2026
Reserved Aug 3, 2026
CISA Vulnrichment
Updated Aug 14, 2026
NVD
Status Analyzed
Modified Aug 25, 2026
Red Hat
Severity Moderate
Public date Aug 12, 2026