PatchSiren cyber security CVE debrief
CVE-2026-18727 Red Hat CVE debrief
A flaw was found in open-iscsi's iscsiuio component. This vulnerability involves an integer underflow and out-of-bounds read during Dynamic Host Configuration Protocol for IPv6 (DHCPv6) packet parsing. Specifically, crafted DHCPv6 Advertise traffic with a short User Datagram Protocol (UDP) length can cause the DHCPv6 payload length to underflow. An unauthenticated attacker on an adjacent network segment can exploit this by sending specially crafted IPv6 UDP traffic while the client is in an active DHCPv6 exchange, leading to a denial of service due to a process crash or service disruption.
- Vendor
- Red Hat
- Product
- Red Hat Enterprise Linux 10
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-12
- Original CVE updated
- 2026-08-25
- Advisory published
- 2026-08-12
- Advisory updated
- 2026-08-25
Who should care
Users of open-iscsi's iscsiuio component, particularly those using Red Hat Enterprise Linux 9.0 and 10.0, should be aware of this vulnerability and take necessary defensive actions. This includes reviewing and implementing vendor-provided patches or updates, monitoring network traffic for suspicious activity, and considering compensating controls such as intrusion detection systems. Security teams and vulnerability management teams should prioritize this vulnerability and coordinate with operators to ensure mitigation.
Technical summary
The vulnerability involves an integer underflow and out-of-bounds read during DHCPv6 packet parsing in the iscsiuio component of open-iscsi. This can be exploited by an unauthenticated attacker on an adjacent network segment by sending specially crafted IPv6 UDP traffic while the client is in an active DHCPv6 exchange, leading to a denial of service due to a process crash or service disruption. Affected products include Red Hat Enterprise Linux 9.0 and 10.0.
Defensive priority
Medium-priority defensive actions are required to address this vulnerability.
Recommended defensive actions
- Apply patches or updates provided by the vendor to address the vulnerability
- Implement network segmentation to limit the attack surface
- Monitor network traffic for suspicious activity
- Consider using compensating controls, such as intrusion detection systems
- Review and verify affected product deployments in managed environments
- Track exceptions and retest remediated assets after applying patches
- Confirm whether asset inventory and exposure review have been completed
Evidence notes
The CVE record and NVD detail provide information on the vulnerability, including its description, CVSS score, and affected products. The iscsiuio component in open-iscsi is vulnerable to an integer underflow and out-of-bounds read during DHCPv6 packet parsing. This can cause a denial of service due to a process crash or service disruption. Users should verify their exposure and review vendor guidance for mitigation.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-18727 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-18727
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-18727 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-18727
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://access.redhat.com/security/cve/CVE-2026-18727
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.