Описание
A flaw was found in open-iscsi. An unauthenticated man-in-the-middle (MITM) attacker can exploit a double-free vulnerability in the iSNS attribute decoder. This can lead to a denial of service (DoS) condition, making the affected system unavailable.
Отчет
This Important severity flaw in open-iscsi allows an unauthenticated Man-in-the-Middle (MITM) attacker to trigger a denial of service in the iSNS attribute decoder. The vulnerability is network-exploitable without requiring user interaction or authentication, posing a significant risk to the availability of iSNS services in environments where the isns-utils package is deployed and the iSNS service is exposed.
Меры по смягчению последствий
If the iSNS service is not actively used, disable it to prevent exploitation.
To disable the isnsd service, execute systemctl disable --now isnsd.
If the iSNS service is required, restrict network access to UDP port 3260 to only trusted hosts and networks using firewall rules.
A service restart may be required for changes to take effect.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | isns-utils | Affected | ||
| Red Hat Enterprise Linux 8 | isns-utils | Affected | ||
| Red Hat Enterprise Linux 9 | isns-utils | Affected |
Показывать по
Дополнительная информация
Статус:
7.5 High
CVSS3
Связанные уязвимости
(A Double Free vulnerability in open-iscsi allows anunauthenticatedMITM ...)
A Double Free vulnerability in open-iscsi allows an unauthenticated MITM attacker to cause DoS. This issue affects open-iscsi: from ? through 56718d4e9d1a4f51c30697b5c0534144bb41c9bb.
A Double Free vulnerability in open-iscsi allows anunauthenticatedMITM ...
A Double Free vulnerability in open-iscsi allows an unauthenticated MITM attacker to cause DoS. This issue affects open-iscsi: from ? through 56718d4e9d1a4f51c30697b5c0534144bb41c9bb.
7.5 High
CVSS3