PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-18727 Red Hat CVE debrief

A flaw was found in open-iscsi's iscsiuio component. This vulnerability involves an integer underflow and out-of-bounds read during Dynamic Host Configuration Protocol for IPv6 (DHCPv6) packet parsing. Specifically, crafted DHCPv6 Advertise traffic with a short User Datagram Protocol (UDP) length can cause the DHCPv6 payload length to underflow. An unauthenticated attacker on an adjacent network segment can exploit this by sending specially crafted IPv6 UDP traffic while the client is in an active DHCPv6 exchange, leading to a denial of service due to a process crash or service disruption.

Vendor
Red Hat
Product
Red Hat Enterprise Linux 10
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-12
Original CVE updated
2026-08-25
Advisory published
2026-08-12
Advisory updated
2026-08-25

Who should care

Users of open-iscsi's iscsiuio component, particularly those using Red Hat Enterprise Linux 9.0 and 10.0, should be aware of this vulnerability and take necessary defensive actions. This includes reviewing and implementing vendor-provided patches or updates, monitoring network traffic for suspicious activity, and considering compensating controls such as intrusion detection systems. Security teams and vulnerability management teams should prioritize this vulnerability and coordinate with operators to ensure mitigation.

Technical summary

The vulnerability involves an integer underflow and out-of-bounds read during DHCPv6 packet parsing in the iscsiuio component of open-iscsi. This can be exploited by an unauthenticated attacker on an adjacent network segment by sending specially crafted IPv6 UDP traffic while the client is in an active DHCPv6 exchange, leading to a denial of service due to a process crash or service disruption. Affected products include Red Hat Enterprise Linux 9.0 and 10.0.

Defensive priority

Medium-priority defensive actions are required to address this vulnerability.

Recommended defensive actions

  • Apply patches or updates provided by the vendor to address the vulnerability
  • Implement network segmentation to limit the attack surface
  • Monitor network traffic for suspicious activity
  • Consider using compensating controls, such as intrusion detection systems
  • Review and verify affected product deployments in managed environments
  • Track exceptions and retest remediated assets after applying patches
  • Confirm whether asset inventory and exposure review have been completed

Evidence notes

The CVE record and NVD detail provide information on the vulnerability, including its description, CVSS score, and affected products. The iscsiuio component in open-iscsi is vulnerable to an integer underflow and out-of-bounds read during DHCPv6 packet parsing. This can cause a denial of service due to a process crash or service disruption. Users should verify their exposure and review vendor guidance for mitigation.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-18727 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-18727

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-18727 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-18727

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.