Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-94428.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-94428
Upstream
Published
2026-07-29T13:18:45Z
Modified
2026-08-28T17:47:40.770348656Z
Summary
CVE-2026-44943 affecting package iscsi-initiator-utils for versions less than 2.1.12-1
Details

An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in open-iscsi allows remote MITM attackersĀ  to create root-owned files outside the database and inject lines into the record.

This issue affects open-iscsi: from through 668ca1df9c9a1e9bdd5c999ae1d67c9c8909237e.

References

Affected packages

Azure Linux:3 / iscsi-initiator-utils

Package

Name
iscsi-initiator-utils
Purl
pkg:rpm/azure-linux/iscsi-initiator-utils

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.1.12-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-94428.json"