A flaw was found in open-iscsi. This vulnerability allows...
Moderate severity
Unreviewed
Published
Aug 13, 2026
to the GitHub Advisory Database
Description
Published by the National Vulnerability Database
Aug 12, 2026
Published to the GitHub Advisory Database
Aug 13, 2026
A flaw was found in open-iscsi. This vulnerability allows a remote attacker on the same local network segment to cause a Denial of Service (DoS) in the iscsiuio daemon. By sending a specially crafted Internet Control Message Protocol version 6 (ICMPv6) Router Advertisement with a zero-length option, the attacker can trigger an infinite loop. This leads to sustained CPU usage, rendering the daemon unresponsive and impacting system availability. A secondary risk of out-of-bounds reads exists with a short IPv6 payload, though no memory corruption or data exposure has been confirmed.
References