CVE-2026-18726 MEDIUM

CVE-2026-18726: Open-iscsi: open-iscsi: denial of service in iscsiuio router advertisement parsing

Vendor Red Hat
Product Red Hat Enterprise Linux 10
Weakness CWE-835
Published August 12, 2026
Last update August 13, 2026

CVSS base score

6.5/10
Attack vector Adjacent
Attack complexity Low
Privileges required None
User interaction None
Confidentiality None
Integrity None

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

What the vulnerability does

01Description

A flaw was found in open-iscsi. This vulnerability allows a remote attacker on the same local network segment to cause a Denial of Service (DoS) in the iscsiuio daemon. By sending a specially crafted Internet Control Message Protocol version 6 (ICMPv6) Router Advertisement with a zero-length option, the attacker can trigger an infinite loop. This leads to sustained CPU usage, rendering the daemon unresponsive and impacting system availability. A secondary risk of out-of-bounds reads exists with a short IPv6 payload, though no memory corruption or data exposure has been confirmed.

Key dates

02Disclosure timeline

August 12, 2026 CVE published
August 13, 2026 Record updated