Impact
An integer underflow and out‑of‑bounds read occurs when open‑iscsi's iscsiuio component parses DHCPv6 Advertise packets with a short UDP length, leading to an unauthenticated denial of service when the client is in an active DHCPv6 exchange. The flaw is a classic integer underflow (CWE‑191) that causes a process crash or service disruption.
Affected Systems
The vulnerability affects Red Hat Enterprise Linux 9 and Red Hat Enterprise Linux 10, specifically the open‑iscsi package’s iscsiuio component. No specific minor versions are listed, so all installations running iscsiuio on these platforms are potentially vulnerable.
Risk and Exploitability
The CVSS score is 6.5, indicating moderate severity, while the EPSS score is not available and the vulnerability is not listed in CISA KEV. An attacker must be on the same Layer 2 segment as the client and must send crafted DHCPv6 Advertise traffic while the iscsiuio service is performing a DHCPv6 exchange. The attack is local to the network and does not provide remote code execution, but it can disrupt availability of iSCSI services.
OpenCVE Enrichment