Impact
A flaw in open-iscsi’s iscsiuio component triggers an integer underflow during the parsing of IPv4 DHCP replies, resulting in an out‑of‑bounds read. When a specially crafted DHCP packet is received, iscsiuio crashes, causing the iSCSI service to become unavailable. The vulnerability is a classic integer underflow (CWE‑191) and does not provide code execution or privilege escalation. It directly affects the availability of iSCSI targets and initiators that rely on iscsiuio for IPv4 DHCP handling.
Affected Systems
Red Hat Enterprise Linux 10 and Red Hat Enterprise Linux 9 systems that have the iscsiuio service enabled and actively handling IPv4 DHCP traffic. The flaw is specific to the iscsiuio component of open‑iscsi.
Risk and Exploitability
The rated CVSS score of 6.5 indicates moderate severity. Exploitation is limited to attackers who can send crafted DHCP packets on the same local network segment; no network traversal or authentication is required. EPSS data is not available, and the vulnerability is not listed in CISA KEV, suggesting that widespread exploitation is not yet confirmed but remains plausible for entities with exposed DHCP traffic.
OpenCVE Enrichment