Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-18724

Источник: debian

Описание

Описание отсутствует

Пакеты

ПакетСтатусВерсия исправленияРелизТип
open-iscsifixed2.1.13-1package
open-iscsino-dsatrixiepackage

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=2461994

  • https://github.com/open-iscsi/open-iscsi/issues/543

  • https://github.com/open-iscsi/open-iscsi/pull/544

  • Fixed by: https://github.com/open-iscsi/open-iscsi/commit/0bdc1ab6718215e67a4acff1e711fc8c6693cff4

Связанные уязвимости

ubuntu
около 1 месяца назад

[Unknown description]

CVSS3: 7.6
redhat
около 1 месяца назад

AI_ONLY_REPORT package: iscsi-initiator-utils-6.2.1.11-0.git4b3e853.el10 ------ Summary: Stack Buffer Overflow in idbm_recinfo_config via Malicious iSCSI Target: a crafted SendTargets TargetName can inject an extra configuration line into a persisted node record and later cause a stack buffer overflow when that record is reparsed. Requirements to exploit: An attacker must control an iSCSI target or tamper with SendTargets discovery traffic, return a crafted `TargetName` containing a newline and oversized injected key or value data, have the victim run persistent discovery, and then trigger a later node-record read such as update or login. Component affected: `iscsi-initiator-utils`; `usr/idbm.c:idbm_recinfo_config`, with attacker-controlled input reaching it through SendTargets handling in `usr/discovery.c` and later record serialization in `usr/idbm.c`. Version affected: `iscsi-initiator-utils-6.2.1.11-0.git4b3e853.el10` Patch available: no released package fix ...