The Open-iSCSI project is a high-performance, transport independent, multi-platform implementation of RFC3720 iSCSI.
Security Fix(es):
An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in open-iscsi allows remote MITM attackers to create root-owned files outside the database and inject lines into the record.
This issue affects open-iscsi: from through 668ca1df9c9a1e9bdd5c999ae1d67c9c8909237e.(CVE-2026-44943)
An Incorrect Authorization vulnerability in open-iscsi allows unprivilidged local users to use the isscsiuio control socket.
This issue affects open-iscsi: from ? through 668ca1df9c9a1e9bdd5c999ae1d67c9c8909237e.(CVE-2026-44944)
A Double Free vulnerability in open-iscsi allows an unauthenticated MITM attacker to cause DoS.
This issue affects open-iscsi: from ? through 56718d4e9d1a4f51c30697b5c0534144bb41c9bb.(CVE-2026-55995)
{
"severity": "High"
}{
"x86_64": [
"open-iscsi-2.1.1-17.oe2003sp4.x86_64.rpm",
"open-iscsi-debuginfo-2.1.1-17.oe2003sp4.x86_64.rpm",
"open-iscsi-debugsource-2.1.1-17.oe2003sp4.x86_64.rpm",
"open-iscsi-devel-2.1.1-17.oe2003sp4.x86_64.rpm"
],
"aarch64": [
"open-iscsi-2.1.1-17.oe2003sp4.aarch64.rpm",
"open-iscsi-debuginfo-2.1.1-17.oe2003sp4.aarch64.rpm",
"open-iscsi-debugsource-2.1.1-17.oe2003sp4.aarch64.rpm",
"open-iscsi-devel-2.1.1-17.oe2003sp4.aarch64.rpm"
],
"src": [
"open-iscsi-2.1.1-17.oe2003sp4.src.rpm"
],
"noarch": [
"open-iscsi-help-2.1.1-17.oe2003sp4.noarch.rpm"
]
}