CVE-2026-18726
Received Received - Intake

Denial of Service in open-iscsi via ICMPv6 Router Advertisement

Vulnerability report for CVE-2026-18726, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-12

Last updated on: 2026-08-12

Assigner: Red Hat, Inc.

Description

A flaw was found in open-iscsi. This vulnerability allows a remote attacker on the same local network segment to cause a Denial of Service (DoS) in the iscsiuio daemon. By sending a specially crafted Internet Control Message Protocol version 6 (ICMPv6) Router Advertisement with a zero-length option, the attacker can trigger an infinite loop. This leads to sustained CPU usage, rendering the daemon unresponsive and impacting system availability. A secondary risk of out-of-bounds reads exists with a short IPv6 payload, though no memory corruption or data exposure has been confirmed.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-12
Last Modified
2026-08-12
Generated
2026-08-13
AI Q&A
2026-08-13
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
open-iscsi open-iscsi *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-835 The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a Denial of Service (DoS) flaw in open-iscsi. A remote attacker on the same local network can exploit it by sending a specially crafted ICMPv6 Router Advertisement with a zero-length option. This triggers an infinite loop in the iscsiuio daemon, causing high CPU usage and making the daemon unresponsive. There is also a secondary risk of out-of-bounds reads with short IPv6 payloads, but no confirmed memory corruption or data exposure.

Detection Guidance

Detecting this vulnerability requires monitoring for unusual CPU usage in the iscsiuio daemon or network traffic containing malformed ICMPv6 Router Advertisements. Check if open-iscsi is installed and running. Use tools like 'top' or 'htop' to observe CPU spikes in iscsiuio. Monitor network traffic with tcpdump or Wireshark for ICMPv6 packets with zero-length options.

Impact Analysis

This vulnerability can impact you by causing your system to become unresponsive due to high CPU usage in the iscsiuio daemon. This leads to a Denial of Service, making the affected service unavailable and potentially disrupting network storage operations.

Mitigation Strategies

Immediately update open-iscsi to the latest patched version. If an update is unavailable, disable the iscsiuio daemon if not required. Restrict network access to trusted sources by configuring firewalls to block ICMPv6 Router Advertisements from untrusted networks. Monitor affected systems for signs of exploitation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-18726. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart