This update for open-iscsi fixes the following issues:
Update to version 2.1.12.suse+0.8f77cf16:
CVE-2026-44943: improper limitation of pathname to a restricted directory allows remote MITM attackers to create
root-owned files outside the database and inject lines into records (bsc#1268353).
CVE-2026-44944: incorrect authorization allows unpriviledged local users to use the isscsiuio control socket
(bsc#1268352).
Changes for open-iscsi:
Version 2.1.12.suse+0.8f77cf16:
Fix security issues recently discovered by Keith at Linneman Labs.
iscsi-init.service: use iscsi-gen-initiatorname.
iscsi-gen-initiatorname: use @IQN_PREFIX@ as default.
Avoid possible double free of found in idbm_rec_update_param.
iscsi: validate interface IP against target address family.