AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-18728

MEDIUM · CVSS 6.5 EPSS 0.20%

Source: NVD + CISA KEV + EPSS · Published 2026-08-13 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

A vulnerability exists in the `iscsiuio` component of open-iscsi, allowing remote attackers on the same local network segment to exploit an integer underflow during IPv4 DHCP parsing. This can lead to a denial of service by sending a crafted DHCP reply that causes the `iscsiuio` process to crash. Organizations utilizing open-iscsi with active DHCP traffic should prioritize addressing this issue to mitigate potential disruptions in service.

CVE
CVE-2026-18728
Severity
MEDIUM
CVSS
6.5
EPSS
0.20%

Original NVD Description

A flaw was found in open-iscsi. An integer underflow vulnerability in the `iscsiuio` component, specifically during IPv4 Dynamic Host Configuration Protocol (DHCP) parsing, allows a remote attacker on the same local network segment to cause a denial of service. By sending a specially crafted IPv4/UDP DHCP reply, the attacker can trigger an out-of-bounds read, leading to the `iscsiuio` process crashing. This issue affects systems where `iscsiuio` is actively handling IPv4 DHCP traffic.