Bug 2508412 (CVE-2026-44944)
| Summary: | CVE-2026-44944 open-iscsi: open-iscsi: Authentication bypass in iscsiuio control socket | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security <prodsec-ir-bot> |
| Status: | NEW --- | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | unspecified | CC: | rhel-process-autobot, watson-tool-maintainers |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in open-iscsi. An incorrect authorization vulnerability allows unprivileged local users to bypass authentication for the iscsiuio control socket. This enables unauthorized access to the control socket, potentially leading to system compromise or disruption of iSCSI (Internet Small Computer System Interface) operations.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2508457 | ||
| Bug Blocks: | |||
|
Description
OSIDB Bzimport
2026-07-29 14:01:55 UTC
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:53845 https://access.redhat.com/errata/RHSA-2026:53845 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:53844 https://access.redhat.com/errata/RHSA-2026:53844 |