Search CVE reports


Toggle filters

1 – 10 of 12 results


CVE-2026-55995

Medium priority
Needs evaluation

A Double Free vulnerability in open-iscsi allows an unauthenticated MITM attacker to cause DoS. This issue affects open-iscsi: from ? through 56718d4e9d1a4f51c30697b5c0534144bb41c9bb.

2 affected packages

open-iscsi, open-isns

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
open-iscsi Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
open-isns Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-44944

Medium priority
Needs evaluation

An Incorrect Authorization vulnerability in open-iscsi allows unprivilidged local users to use the isscsiuio control socket. This issue affects open-iscsi: from ? through 668ca1df9c9a1e9bdd5c999ae1d67c9c8909237e.

1 affected package

open-iscsi

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
open-iscsi Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-44943

Medium priority
Needs evaluation

An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in open-iscsi allows remote MITM attackers  to create root-owned files outside the database and inject lines into the record. This...

1 affected package

open-iscsi

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
open-iscsi Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2020-24335

Medium priority
Not affected

An issue was discovered in uIP through 1.0, as used in Contiki and Contiki-NG. Domain name parsing lacks bounds checks, allowing an attacker to corrupt memory with crafted DNS packets.

1 affected package

open-iscsi

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
open-iscsi Not affected Not affected
Show less packages

CVE-2020-17438

Medium priority
Not affected

An issue was discovered in uIP 1.0, as used in Contiki 3.0 and other products. The code that reassembles fragmented packets fails to properly validate the total length of an incoming packet specified in its IP header, as well as...

1 affected package

open-iscsi

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
open-iscsi Not affected Not affected
Show less packages

CVE-2020-17437

Low priority

Some fixes available 8 of 9

An issue was discovered in uIP 1.0, as used in Contiki 3.0 and other products. When the Urgent flag is set in a TCP packet, and the stack is configured to ignore the urgent data, the stack attempts to use the value of the Urgent...

1 affected package

open-iscsi

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
open-iscsi Fixed Fixed Fixed
Show less packages

CVE-2020-13988

Low priority

Some fixes available 8 of 9

An issue was discovered in Contiki through 3.0. An Integer Overflow exists in the uIP TCP/IP Stack component when parsing TCP MSS options of IPv4 network packets in uip_process in net/ipv4/uip.c.

1 affected package

open-iscsi

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
open-iscsi Fixed Fixed Fixed
Show less packages

CVE-2020-13987

Low priority

Some fixes available 8 of 9

An issue was discovered in Contiki through 3.0. An Out-of-Bounds Read vulnerability exists in the uIP TCP/IP Stack component when calculating the checksums for IP packets in upper_layer_chksum in net/ipv4/uip.c.

1 affected package

open-iscsi

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
open-iscsi Fixed Fixed Fixed
Show less packages

CVE-2017-17840

Medium priority
Ignored

An issue was discovered in Open-iSCSI through 2.0.875. A local attacker can cause the iscsiuio server to abort or potentially execute code by sending messages with incorrect lengths, which (due to lack of checking) can lead to...

1 affected package

open-iscsi

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
open-iscsi Not affected
Show less packages

CVE-2009-1297

Low priority

Some fixes available 1 of 4

iscsi_discovery in open-iscsi in SUSE openSUSE 10.3 through 11.1 and SUSE Linux Enterprise (SLE) 10 SP2 and 11, and other operating systems, allows local users to overwrite arbitrary files via a symlink attack on an unspecified...

1 affected package

open-iscsi

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
open-iscsi
Show less packages