Description
A Double Free vulnerability in open-iscsi allows an unauthenticated MITM attacker to cause DoS.






This issue affects open-iscsi: from ? through 56718d4e9d1a4f51c30697b5c0534144bb41c9bb.
Published: 2026-07-29
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is a double‑free flaw in the iSNS attribute decoder that allows an unauthenticated man‑in‑the‑middle attacker to trigger a denial of service by corrupting memory. The double free directly leads to a crash of the iSCSI initiator or target, resulting in service interruption. The weakness is represented by CWE‑415 (Double Free) and CWE‑763 (Memory Management Exceeded Boundary).

Affected Systems

The flaw affects all releases of open‑iscsi prior to the commit identified as 56718d4e9d1a4f51c30697b5c0534144bb41c9bb. These include the default iSCSI initiator and target implementations provided by the open‑iscsi project.

Risk and Exploitability

The CVSS score of 8.7 indicates high severity. Although the EPSS score is reported as less than 1% and the vulnerability is not listed in CISA’s KEV catalog, the attack vector is inferred to be network‑based, allowing a remote, unauthenticated attacker to perform a man‑in‑the‑middle operation and trigger the service crash. Given the nature of the error, exploitation requires a network path to the iSNS service and can be achieved without authentication, making the risk significant for exposed systems.

Generated by OpenCVE AI on August 3, 2026 at 13:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to a release of open‑iscsi that follows commit 56718d4e9d1a4f51c30697b5c0534144bb41c9bb or later.
  • If an immediate patch is unavailable, disable iSNS support in the open‑iscsi configuration or remove the iSNS module entirely to eliminate the attack surface.
  • Apply network segmentation or firewall rules to block unauthorized iSNS traffic and monitor for anomalous connection attempts.

Generated by OpenCVE AI on August 3, 2026 at 13:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Open-iscsi Project
Open-iscsi Project open-iscsi
Vendors & Products Open-iscsi Project
Open-iscsi Project open-iscsi

Thu, 30 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-763
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Important


Wed, 29 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 29 Jul 2026 14:00:00 +0000

Type Values Removed Values Added
Description A Double Free vulnerability in open-iscsi allows an unauthenticated MITM attacker to cause DoS. This issue affects open-iscsi: from ? through 56718d4e9d1a4f51c30697b5c0534144bb41c9bb.
Title Double-free in the iSNS attribute decoder in open-iscsi
Weaknesses CWE-415
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Open-iscsi Project Open-iscsi
cve-icon MITRE

Status: PUBLISHED

Assigner: suse

Published:

Updated: 2026-07-29T14:43:55.157Z

Reserved: 2026-06-18T09:26:55.987Z

Link: CVE-2026-55995

cve-icon Vulnrichment

Updated: 2026-07-29T14:43:50.383Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-07-29T14:16:31.423

Modified: 2026-07-30T16:43:03.817

Link: CVE-2026-55995

cve-icon Redhat

Severity : Important

Publid Date: 2026-07-29T13:43:22Z

Links: CVE-2026-55995 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T13:30:04Z

Weaknesses