Bug 2508414 (CVE-2026-55995) - CVE-2026-55995 open-isns: open-iscsi: Denial of Service via double-free in iSNS attribute decoder
Summary: CVE-2026-55995 open-isns: open-iscsi: Denial of Service via double-free in iS...
Keywords:
Status: NEW
Alias: CVE-2026-55995
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2508456
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-07-29 14:02 UTC by OSIDB Bzimport
Modified: 2026-08-11 20:10 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2026:53846 0 None None None 2026-08-11 19:26:13 UTC
Red Hat Product Errata RHSA-2026:53847 0 None None None 2026-08-11 19:38:02 UTC
Red Hat Product Errata RHSA-2026:53848 0 None None None 2026-08-11 20:10:26 UTC

Description OSIDB Bzimport 2026-07-29 14:02:04 UTC
A Double Free vulnerability in open-iscsi allows an unauthenticated MITM attacker to cause DoS.






This issue affects open-iscsi: from ? through 56718d4e9d1a4f51c30697b5c0534144bb41c9bb.

Comment 3 errata-xmlrpc 2026-08-11 19:26:12 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:53846 https://access.redhat.com/errata/RHSA-2026:53846

Comment 4 errata-xmlrpc 2026-08-11 19:38:02 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:53847 https://access.redhat.com/errata/RHSA-2026:53847

Comment 5 errata-xmlrpc 2026-08-11 20:10:25 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:53848 https://access.redhat.com/errata/RHSA-2026:53848


Note You need to log in before you can comment on or make changes to this bug.