Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-95925.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-95925
Upstream
  • CVE-2026-18726
Published
2026-08-12T22:17:14Z
Modified
2026-08-30T05:26:50Z
Summary
CVE-2026-18726 affecting package iscsi-initiator-utils 2.1.12-1
Details

A flaw was found in open-iscsi. This vulnerability allows a remote attacker on the same local network segment to cause a Denial of Service (DoS) in the iscsiuio daemon. By sending a specially crafted Internet Control Message Protocol version 6 (ICMPv6) Router Advertisement with a zero-length option, the attacker can trigger an infinite loop. This leads to sustained CPU usage, rendering the daemon unresponsive and impacting system availability. A secondary risk of out-of-bounds reads exists with a short IPv6 payload, though no memory corruption or data exposure has been confirmed.

References

Affected packages

Azure Linux:3 / iscsi-initiator-utils

Package

Name
iscsi-initiator-utils
Purl
pkg:rpm/azure-linux/iscsi-initiator-utils

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
2.1.12-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-95925.json"