Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
To mitigate this issue, restrict ICMPv6 Router Advertisements from untrusted sources on any network segment where `iscsiuio` interfaces are exposed. Alternatively, disable IPv6 Router Advertisement processing on affected interfaces if not operationally required. This may involve configuring firewall rules to filter ICMPv6 type 134 messages or adjusting network interface settings to prevent RA-driven IPv6 configuration. A service restart may be required for changes to take effect.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 12 Aug 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in open-iscsi. This vulnerability allows a remote attacker on the same local network segment to cause a Denial of Service (DoS) in the iscsiuio daemon. By sending a specially crafted Internet Control Message Protocol version 6 (ICMPv6) Router Advertisement with a zero-length option, the attacker can trigger an infinite loop. This leads to sustained CPU usage, rendering the daemon unresponsive and impacting system availability. A secondary risk of out-of-bounds reads exists with a short IPv6 payload, though no memory corruption or data exposure has been confirmed. | |
| Title | Open-iscsi: open-iscsi: denial of service in iscsiuio router advertisement parsing | |
| First Time appeared |
Redhat
Redhat enterprise Linux |
|
| Weaknesses | CWE-835 | |
| CPEs | cpe:/o:redhat:enterprise_linux:10 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat enterprise Linux |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-08-12T21:13:47.604Z
Reserved: 2026-08-03T17:55:50.945Z
Link: CVE-2026-18726
No data.
Status : Received
Published: 2026-08-12T22:17:14.557
Modified: 2026-08-12T22:17:14.557
Link: CVE-2026-18726
No data.
OpenCVE Enrichment
No data.