CVE-2026-18728Disclosure(redhat / enterprise_linux)

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw was found in open-iscsi. An integer underflow vulnerability in the `iscsiuio` component, specifically during IPv4 Dynamic Host Configuration Protocol (DHCP) parsing, allows a remote attacker on the same local network segment to cause a denial of service. By sending a specially crafted IPv4/UDP DHCP reply, the attacker can trigger an out-of-bounds read, leading to the `iscsiuio` process crashing. This issue affects systems where `iscsiuio` is actively handling IPv4 DHCP traffic.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-191

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • enterprise_linux

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-08-13); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
enterprise_linux

2 versions affected across 1 product

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-08-13: 2Mentions · 2026-08-15: 1Technical Details · 2026-08-13: 2Technical Details · 2026-08-15: 108-1308-15
Signal classification1 categories
Disclosure
3100.0%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-08-132
Disclosure2
2026-08-151
Disclosure1
Full discourse3 posts
  • Ciberseguridad LATAM@CibersegLATAM
    Disclosure

    El componente iscsiuio de open-iscsi — utilizado para gestionar conexiones iSCSI sobre redes IP — contiene una vulnerabilidad de severidad media (CVE-2026-18728) que permite

    Post summary

    The text announces a medium‑severity vulnerability in the iscsiuio component of open‑iscsi, identified as CVE-2026‑18728.

    10000188
    22.5K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-18728 A flaw was found in open-iscsi. An integer underflow vulnerability in the `iscsiuio` component, specifically during IPv4 Dynamic Host Configuration Protocol (DHCP) pa… https://www.cve.org/CVERecord?id=CVE-2026-18728 ----- Traducción: Se identificó una … https://infoflow.cloud`

    Post summary

    An integer underflow vulnerability in open‑iscsi's iscsiuio component during IPv4 DHCP has been identified (CVE-2026-18728). No PoC, exploit, or patch information is provided, only the technical nature of the flaw.

    0000029
    97 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-18728 A flaw was found in open-iscsi. An integer underflow vulnerability in the `iscsiuio` component, specifically during IPv4 Dynamic Host Configuration Protocol (DHCP) pa… https://www.cve.org/CVERecord?id=CVE-2026-18728

    Post summary

    A new integer underflow flaw was discovered in open‑iscsi's iscsiuio component during IPv4 DHCP handling.

    00000843
    57.9K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
OSredhatenterprise_linux10.0--
OSredhatenterprise_linux9.0--

Explore more