Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| open-iscsi | fixed | 2.1.13-1 | package | |
| open-iscsi | no-dsa | trixie | package |
Примечания
https://bugzilla.redhat.com/show_bug.cgi?id=2461994
https://github.com/open-iscsi/open-iscsi/issues/543
https://github.com/open-iscsi/open-iscsi/pull/544
Fixed by: https://github.com/open-iscsi/open-iscsi/commit/0bdc1ab6718215e67a4acff1e711fc8c6693cff4
Связанные уязвимости
AI_ONLY_REPORT package: iscsi-initiator-utils-6.2.1.11-0.git4b3e853.el10 ------ Summary: Stack Buffer Overflow in idbm_recinfo_config via Malicious iSCSI Target: a crafted SendTargets TargetName can inject an extra configuration line into a persisted node record and later cause a stack buffer overflow when that record is reparsed. Requirements to exploit: An attacker must control an iSCSI target or tamper with SendTargets discovery traffic, return a crafted `TargetName` containing a newline and oversized injected key or value data, have the victim run persistent discovery, and then trigger a later node-record read such as update or login. Component affected: `iscsi-initiator-utils`; `usr/idbm.c:idbm_recinfo_config`, with attacker-controlled input reaching it through SendTargets handling in `usr/discovery.c` and later record serialization in `usr/idbm.c`. Version affected: `iscsi-initiator-utils-6.2.1.11-0.git4b3e853.el10` Patch available: no released package fix ...