Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-55995

Опубликовано: 29 июл. 2026
Источник: redhat
CVSS3: 7.5

Описание

A flaw was found in open-iscsi. An unauthenticated man-in-the-middle (MITM) attacker can exploit a double-free vulnerability in the iSNS attribute decoder. This can lead to a denial of service (DoS) condition, making the affected system unavailable.

Отчет

This Important severity flaw in open-iscsi allows an unauthenticated Man-in-the-Middle (MITM) attacker to trigger a denial of service in the iSNS attribute decoder. The vulnerability is network-exploitable without requiring user interaction or authentication, posing a significant risk to the availability of iSNS services in environments where the isns-utils package is deployed and the iSNS service is exposed.

Меры по смягчению последствий

If the iSNS service is not actively used, disable it to prevent exploitation. To disable the isnsd service, execute systemctl disable --now isnsd. If the iSNS service is required, restrict network access to UDP port 3260 to only trusted hosts and networks using firewall rules. A service restart may be required for changes to take effect.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10isns-utilsAffected
Red Hat Enterprise Linux 8isns-utilsAffected
Red Hat Enterprise Linux 9isns-utilsAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-763
https://bugzilla.redhat.com/show_bug.cgi?id=2508414open-isns: open-iscsi: Denial of Service via double-free in iSNS attribute decoder

7.5 High

CVSS3

Связанные уязвимости

ubuntu
6 дней назад

(A Double Free vulnerability in open-iscsi allows anunauthenticatedMITM ...)

nvd
6 дней назад

A Double Free vulnerability in open-iscsi allows an unauthenticated MITM attacker to cause DoS. This issue affects open-iscsi: from ? through 56718d4e9d1a4f51c30697b5c0534144bb41c9bb.

debian
6 дней назад

A Double Free vulnerability in open-iscsi allows anunauthenticatedMITM ...

github
6 дней назад

A Double Free vulnerability in open-iscsi allows an unauthenticated MITM attacker to cause DoS. This issue affects open-iscsi: from ? through 56718d4e9d1a4f51c30697b5c0534144bb41c9bb.

7.5 High

CVSS3