Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-95919.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-95919
Upstream
  • CVE-2026-18728
Published
2026-08-13T04:17:19Z
Modified
2026-08-30T05:26:50Z
Summary
CVE-2026-18728 affecting package iscsi-initiator-utils 2.1.12-1
Details

A flaw was found in open-iscsi. An integer underflow vulnerability in the iscsiuio component, specifically during IPv4 Dynamic Host Configuration Protocol (DHCP) parsing, allows a remote attacker on the same local network segment to cause a denial of service. By sending a specially crafted IPv4/UDP DHCP reply, the attacker can trigger an out-of-bounds read, leading to the iscsiuio process crashing. This issue affects systems where iscsiuio is actively handling IPv4 DHCP traffic.

References

Affected packages

Azure Linux:3 / iscsi-initiator-utils

Package

Name
iscsi-initiator-utils
Purl
pkg:rpm/azure-linux/iscsi-initiator-utils

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
2.1.12-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-95919.json"