CVE-2026-18728: Red Hat Enterprise Linux
Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.
A flaw was found in open-iscsi. An integer underflow vulnerability in the `iscsiuio` component, specifically during IPv4 Dynamic Host Configuration Protocol (DHCP) parsing, allows a remote attacker on the same local network segment to cause a denial of service. By sending a specially crafted IPv4/UDP DHCP reply, the attacker can trigger an out-of-bounds read, leading to the `iscsiuio` process crashing. This issue affects systems where `iscsiuio` is actively handling IPv4 DHCP traffic.
Affected products
- Red Hat Enterprise Linux: version 9.0 only; version 10.0 only
Published 2026-08-13. Last modified 2026-08-25.