Red Hat Linux RHEL & SELinux Vulnerabilities & Security Advisories
1648 advisories tracked · Red Hat Security Data API · 2 listed in the CISA Known Exploited Vulnerabilities catalog
Every row below is a published Red Hat Linux advisory that VulniPulse classified as RHEL & SELinux, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 35 critical, 622 high, 819 medium, 170 low.
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat RHEL & SELinux advisories
Medium [CVE-2026-72817] IP spoofing via X-Forwarded-For header manipulation
go-chi/chi versions 0.9.0 before 5.3.0 contains an IP spoofing vulnerability in the RealIP middleware, which resolves the request source IP (Request. RemoteAddr) using the first IP in the X-Forwarded-For header without validating trusted proxies. A malicious client can prepend a forged IP as the first value of the X-Forwarded-For header to spoof the request source IP, potentially bypassing access controls or falsifying request logs. A flaw was found in the `go-chi/chi` component. A remote attacker can exploit this by prepending a forged IP address to the `X-Forwarded-For` header, leading to IP spoofing. The middleware parses the first IP address in the `X-Forwarded-For` header without verifying if the immediate HTTP proxy peer is trusted. An unauthenticated attacker can prepend an arbitrary IP address to the `X-Forwarded-For` header, causing applications relying on `RealIP` for request context to misidentify the client source. This enables bypassing application-level IP-based access control lists (ACLs) or spoofing identity in audit logs. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N). Weakness: CWE-501. Affected products named by the advisory: Red Hat Hardened Images; Cryostat 4; External Secrets Operator for Red Hat OpenShift; Gatekeeper 3; and 19 more.
Medium [CVE-2026-19617] Denial of Service via uncontrolled recursion in config parser
A flaw was found in libdm. A local attacker could craft a malicious Logical Volume Manager (LVM) metadata configuration with deeply nested structures. This could lead to uncontrolled recursion in the libdm configuration file parser, exhausting the stack and causing any LVM command reading the metadata to crash. This vulnerability results in a Denial of Service (DoS) for affected systems. This Moderate impact flaw in libdm's configuration parser can lead to a denial of service. This primarily affects systems where untrusted users have write access to LVM metadata. Red Hat severity: Moderate — CVSS 5.5 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-770. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4. Under investigation: Red Hat Hardened Images. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: lvm2.
Medium [CVE-2026-19730] Quadlet install --replace non-truncating write retains removed host-access directives
The 'podman quadlet install --replace' command opens the existing destination file with O_CREATE|O_WRONLY but omits O_TRUNC. When the initial reflink copy attempt fails (common on non-reflink-capable filesystems including many RHEL default XFS configurations), the fallback in ReflinkOrCopy uses io.Copy which performs a non-truncating write. If the original Quadlet is larger than the new Quadlet, the file is not truncated and content from the original is preserved. The command completes with no warning. There is no risk of information leakage as the user already had access to the Quadlet in order to replace it, and in most cases, this would only lead to invalid Quadlet files. However, security-related options from the end of the old Quadlet could be included in the new Quadlet, and if the truncation resulted in a valid Quadlet file, this could result in undesirable behavior. For example, running podman quadlet install --replace to remove a single line from the end of a Quadlet - including security-sensitive content, like AddCapability - will fail, and the option will continue to be used. Further, with Volume Quadlets, this can include additional mounts which can cause content to be unintentionally exposed into containers. If, later, the image is updated then compromised content might be leaked to an attacker.
Medium [CVE-2026-70453] Denial of Service via Algorithmic Complexity
rsync before 3.5.0 contains an algorithmic complexity vulnerability in the hash_search() function that allows a remote attacker to cause a denial of service by delivering a carefully constructed file list. A sender can exploit the quadratic-time worst-case behavior in hash lookups to exhaust receiver CPU resources with a modest number of crafted entries, causing a sustained denial of service. A flaw was found in rsync. By sending a specially crafted file list, an attacker can exhaust the receiver's CPU resources, leading to service unavailability. This is particularly relevant in Red Hat environments where rsync is used for remote file synchronization and may be exposed to untrusted networks. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-770. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat OpenShift Container Platform 4. Red Hat fixing advisory: RHSA-2026:67463, RHSA-2026:67462. Affected products named by the advisory: Red Hat package: rsync.
Medium [CVE-2026-70454] TLS Certificate Validation Bypass allows interception of encrypted sessions
rsync 3.2.0 through 3.2.3 (openssl mode) and rsync-ssl through 3.4.4 (stunnel mode) contain a TLS certificate validation vulnerability that allows on-path attackers to intercept encrypted sessions by presenting self-signed or otherwise invalid certificates. Attackers can exploit the failure to validate server TLS certificates against a trusted CA or verify certificate hostname matching to decrypt or tamper with rsync session content without detection by the client. A flaw was found in the rsync-ssl wrapper script's TLS certificate validation. The vulnerability arises from insufficient TLS certificate validation, enabling an attacker to present invalid certificates and compromise data integrity and confidentiality without detection. Exploitation requires an attacker to be positioned to intercept network traffic between the rsync client and server. Red Hat severity: Moderate — CVSS 6.8 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N). Weakness: CWE-295. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4. Red Hat fixing advisory: RHSA-2026:67463, RHSA-2026:67462. Affected products named by the advisory: Red Hat package: rsync.
Medium [CVE-2026-70462] Denial of Service via signed integer overflow in I/O timeout
rsync 3.1.0 before 3.5.0 contains a signed integer overflow vulnerability in the I/O timeout implementation that allows attackers to permanently disable connection timeouts by injecting MSG_IO_TIMEOUT messages carrying non-positive (zero or negative) values. Attackers can craft malicious MSG_IO_TIMEOUT messages that cause the timeout variable to wrap to a non-positive value, preventing the timeout check from firing and enabling idle or stalled connections to hold daemon slots indefinitely, leading to resource exhaustion. A flaw was found in rsync. A remote attacker can exploit a signed integer overflow vulnerability in the I/O timeout implementation by sending specially crafted messages. These messages can disable connection timeouts, causing idle or stalled connections to persist indefinitely. This leads to resource exhaustion, preventing legitimate users from accessing the rsync service and resulting in a denial of service. This is a Moderate denial of service flaw in rsync, where a remote, unauthenticated attacker can exhaust system resources. The impact is limited to denial of service and does not allow for arbitrary code execution or data compromise. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-190.
Medium [CVE-2026-53794] Denial of Service via --max-alloc=0 logic error
rsync before 3.5.0 contains a logic error in --max-alloc handling that allows a sender or configuration setting --max-alloc=0 to disable allocation sanity checks entirely rather than enforcing a zero-byte cap. Attackers can exploit this flaw to cause the receiver to attempt unbounded memory allocations for file list and data structures, potentially exhausting available memory and causing a denial of service. A flaw was found in rsync. This vulnerability in rsync is rated as Important. A remote attacker can exploit a logic error in the `--max-alloc` handling by providing `--max-alloc=0`, which disables memory allocation sanity checks. This can lead to unbounded memory consumption on the receiving system, resulting in a denial of service without requiring authentication or user interaction. Red Hat systems using rsync, particularly in daemon mode or when processing untrusted data, are at risk. Red Hat severity: Moderate — CVSS 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L). Weakness: CWE-770. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: rsync.
Medium [CVE-2026-53792] Denial of Service via out-of-bounds read with crafted checksum block
rsync before 3.5.0 contains an out-of-bounds read vulnerability in the sender-side block matching logic that allows a malicious receiver to trigger memory access before the start of an allocated buffer by sending a crafted checksum block with a length of zero. Attackers can send a specially crafted checksum set containing a zero-length block to cause a negative offset calculation during delta computation, resulting in an out-of-bounds read of file data buffer memory on the sender side. A flaw was found in rsync. This can lead to a denial of service on the sender side. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-129. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: rsync.
Medium [CVE-2026-6470] Denial of Service via missing authorization in DDL commands
Missing authorization in PostgreSQL DDL commands allows an object creator to achieve denial of service against ALTER and DROP of the type, via creating a dependency on the type. Many DDL operations did check the privilege, but assigning a range subtype and referencing the type from an SQL expression did not. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected. A flaw was found in PostgreSQL where missing authorization checks in DDL commands allow an authenticated user to create unauthorized dependencies on a data type (such as when assigning a range subtype or referencing the type in an SQL expression). This allows the user to block legitimate owners from altering or dropping that type, resulting in a targeted denial-of-service condition on the affected database object. This Moderate impact flaw allows an authenticated user with object creation rights to cause a targeted denial of service in PostgreSQL. Missing authorization checks during specific DDL operations allow an attacker to create type dependencies that block legitimate ALTER and DROP commands, preventing routine administrative management of affected data types. Red Hat severity: Moderate — CVSS 4.3 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L). Weakness: CWE-862.
Medium [CVE-2026-18024] Information disclosure via buffer over-read in ascii function
Buffer over-read in PostgreSQL ascii() SQL function allows a user to disclose up to 3 bytes after the end of a specific allocation, via a crafted text value. This is the same class of defect that CVE-2026-2006 fixed, though this instance has less impact. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected. A flaw was found in PostgreSQL. This could lead to limited information disclosure. This Moderate impact information disclosure flaw in PostgreSQL's `ascii()` SQL function allows an authenticated attacker to read up to 3 bytes of memory beyond an allocated buffer by providing a specially crafted text value. The limited scope of data disclosure contributes to its Moderate severity. Red Hat severity: Moderate — CVSS 4.3 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N). Weakness: CWE-126. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Self-service automation portal 2. Red Hat lists Red Hat Hardened Images as not affected. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: postgresql16; Red Hat package: postgresql18.
Medium [CVE-2026-14681] Improper enforcement of GSSAPI encryption via direct TLS connection
Improper enforcement of message integrity in PostgreSQL GSSAPI support allows a user to negotiate GSSAPI contrary to pg_hba.conf rules, via initial direct TLS connection. Despite a pg_hba.conf that appears to require GSSAPI, the connection may exchange data over TLS encryption alone. If the TLS settings are more permissive than the GSS settings, the connection may continue with lesser protection. Within major versions 17-18, minor versions before PostgreSQL 18.5 and 17.11 are affected. A flaw was found in PostgreSQL. This enables the connection to proceed with only TLS encryption, even when GSSAPI is required. This Moderate severity flaw in PostgreSQL's GSSAPI support allows a remote, authenticated attacker with low privileges to bypass `pg_hba.conf` rules requiring GSSAPI encryption. By initiating a direct TLS connection, the attacker can force a less secure connection if TLS settings are more permissive, potentially compromising data integrity and confidentiality. The high attack complexity reduces the overall risk. Red Hat severity: Moderate — CVSS 4.2 (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N). Weakness: CWE-924. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: postgresql18.
Medium [CVE-2026-14678] Information disclosure via buffer over-read in pg_trgm
Buffer over-read in PostgreSQL pg_trgm index picksplit function reads past end of a heap buffer. This might allow a table maintainer to infer limited memory values, via the lossy signal of index split choices. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected. A flaw was found in PostgreSQL. This Moderate impact information disclosure flaw in PostgreSQL's pg_trgm extension requires a table maintainer to exploit, limiting the attack surface to privileged database users. Red Hat severity: Moderate — CVSS 4.3 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N). Weakness: CWE-126. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Self-service automation portal 2. Red Hat lists Red Hat Hardened Images as not affected. Will not fix / out of support: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: postgresql16; Red Hat package: postgresql18.
Medium [CVE-2026-14672] User existence oracle in SCRAM authentication
Observable response discrepancy in PostgreSQL SCRAM authentication allows an unauthenticated user to test the existence of a user via observing the SCRAM iteration count. This requires the probed user to have a non-default scram_iterations count, because the authentication challenge for a nonexistent user reports the default scram_iterations. Within major versions 16-18, minor versions before PostgreSQL 18.5, 17.11, and 16.15 are affected. Unauthenticated attackers can verify if a specific user exists by observing the authentication iteration count, provided the targeted user is configured with a non-default scram_iterations value. A moderate-severity vulnerability in PostgreSQL allows unauthenticated attackers to enumerate valid users. By observing discrepancies in SCRAM authentication responses, attackers can identify users configured with a non-default scram_iterations count, which may facilitate targeted brute-force attacks. Red Hat severity: Moderate — CVSS 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N). Weakness: CWE-204. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: postgresql16; Red Hat package: postgresql18.
Medium [CVE-2026-14666] Row security caching disregards role modifications leading to unauthorized data access
Incomplete tracking in PostgreSQL of changes to role membership, role attributes, and database ownership allows a query to continue using cached row-level security policies after those changes require a different policy, via plan reuse. Stale policies continue until some other event invalidates the cache or connection termination ends the session. This permits a user to complete reads and modifications that were recently permitted but now forbidden. An attacker must tailor an attack to a particular application's pattern of privilege removal and role-specific row security policies. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected. Active sessions may continue using cached, outdated security policies, enabling unauthorized read or write access to data. Exploitation requires the attacker to understand the application's specific privilege removal configurations. This vulnerability in PostgreSQL is of Moderate impact. It allows a low-privileged authenticated user to bypass row-level security policies due to stale cached plans, potentially leading to unauthorized data access or modification. Red Hat severity: Moderate — CVSS 4.2 (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N). Weakness: CWE-524. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Self-service automation portal 2.
Medium [CVE-2026-14663] PostgreSQL pgcrypto: Information disclosure via cleartext storage with disabled ciphers
Cleartext storage in PostgreSQL pgcrypto disabled ciphers allows a user to recover cleartext, via direct observation of the faulty ciphertext. The OpenSSL version and OpenSSL configuration determine the disabled ciphers. If the application accepts encrypted data as input, decryption will succeed even with the wrong key. This in turn loses the modest protection from the Modification Detection Code (MDC). Affected functions are pgp_sym_encrypt, pgp_sym_decrypt, pgp_pub_encrypt, pgp_pub_decrypt, pgp_sym_encrypt_bytea, pgp_sym_decrypt_bytea, pgp_pub_encrypt_bytea, and pgp_pub_decrypt_bytea. This is a Moderate impact flaw in PostgreSQL's pgcrypto module where disabled ciphers can lead to information disclosure. This vulnerability primarily affects instances utilizing the pgcrypto module for encryption, potentially exposing sensitive data if specific OpenSSL configurations disable certain ciphers. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N). Weakness: CWE-312. Affected Red Hat products: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Self-service automation portal 2. Red Hat fixing advisory: RHSA-2026:54751, RHSA-2026:57198.
Medium [CVE-2026-73584] Privileged file corruption and denial of service via insecure temporary file handling
A flaw was found in sblim-sfcb. A local, low-privileged attacker can exploit a race condition during privileged instance migration by manipulating a temporary file in the `/tmp` directory. By repeatedly recreating a symbolic link, the attacker can redirect privileged output to an arbitrary file. This can lead to privileged file corruption or a denial of service (DoS) on the system. Exploitation requires a local low-privileged user to win a race during privileged `sfcbrepos` instance migration, which must be enabled and have specific repository content. The high attack complexity and specific preconditions limit its broader impact. Red Hat severity: Moderate — CVSS 6.3 (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H). Weakness: CWE-377. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: sblim-sfcb.
Medium [CVE-2026-73583] Unsafe deserialization in sblim-sfcb provider-manager IPC allows out-of-bounds memory access via malformed OperationHdr
A flaw was found in sblim-sfcb. A local attacker with access to the system can exploit an unsafe deserialization vulnerability in the provider-manager's inter-process communication (IPC) message parsing. By sending a specially crafted message, the attacker can cause out-of-bounds memory access, leading to the termination of the provider-manager process and a denial of service. This could also potentially result in limited unintended information disclosure. This vulnerability has a Moderate impact. Exploitation depends on local IPC configuration and socket permissions, limiting its broader impact. Red Hat severity: Moderate — CVSS 6.6 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H). Weakness: CWE-125. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: sblim-sfcb.
Medium [CVE-2026-73585] Insecure temporary file creation in sblim-cmpi-base provider registration scripts allows local symlink attack
A flaw was found in sblim-cmpi-base. Insecure temporary file creation in the provider registration scripts allows a local unprivileged user to perform a symlink attack. By creating a symlink in a world-writable directory, an attacker can redirect privileged writes to an arbitrary file during script execution in a privileged context. This can lead to the overwrite of root-owned files, potentially disrupting system services or operation. Exploitation is conditional on the script running with elevated privileges and may be mitigated by sticky-directory symlink protections. Exploitation requires specific conditions, including a privileged script execution and systems without sticky-directory symlink protections, which reduces its overall impact. Red Hat severity: Moderate — CVSS 6.3 (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H). Weakness: CWE-377. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: sblim-cmpi-base.
Medium [CVE-2026-18728] Integer underflow in iscsiuio IPv4 DHCP parsing
A flaw was found in open-iscsi. An integer underflow vulnerability in the `iscsiuio` component, specifically during IPv4 Dynamic Host Configuration Protocol (DHCP) parsing, allows a remote attacker on the same local network segment to cause a denial of service. By sending a specially crafted IPv4/UDP DHCP reply, the attacker can trigger an out-of-bounds read, leading to the `iscsiuio` process crashing. This issue affects systems where `iscsiuio` is actively handling IPv4 DHCP traffic. This flaw in `iscsi-initiator-utils` is rated Moderate. It allows an adjacent-network attacker to trigger a denial of service by sending a crafted IPv4/UDP DHCP reply to systems where `iscsiuio` is configured to use IPv4 DHCP. Exploitation requires specific network conditions and a vulnerable configuration, limiting its broader impact. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-191. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: iscsi-initiator-utils.
Medium [CVE-2026-18727] Integer underflow in iscsiuio DHCPv6 parsing
A flaw was found in open-iscsi's iscsiuio component. This vulnerability involves an integer underflow and out-of-bounds read during Dynamic Host Configuration Protocol for IPv6 (DHCPv6) packet parsing. Specifically, crafted DHCPv6 Advertise traffic with a short User Datagram Protocol (UDP) length can cause the DHCPv6 payload length to underflow. An unauthenticated attacker on an adjacent network segment can exploit this by sending specially crafted IPv6 UDP traffic while the client is in an active DHCPv6 exchange, leading to a denial of service due to a process crash or service disruption. This Moderate flaw in `iscsi-initiator-utils` can lead to an adjacent-network denial of service in the `iscsiuio` DHCPv6 client path. Exploitation requires an attacker on the same L2 segment to send crafted DHCPv6 Advertise traffic while the client is in an active DHCPv6 exchange, limiting its broader impact. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-191. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: iscsi-initiator-utils.