CVE-2026-55995: Double-free in the iSNS attribute decoder in open-iscsi
A Double Free vulnerability in open-iscsi allows an unauthenticated MITM attacker to cause DoS.
This issue affects open-iscsi: from ? through 56718d4e9d1a4f51c30697b5c0534144bb41c9bb.
Other sources
Double-free in the iSNS attribute decoder in open-iscsi
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 0.102-2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-55995?
CVE-2026-55995 has a high severity rating of 8.7 on the CVSS scale.
How do I fix CVE-2026-55995?
To mitigate CVE-2026-55995, it is recommended to update to the latest version of open-iscsi that addresses this vulnerability.
What type of vulnerability is CVE-2026-55995?
CVE-2026-55995 is classified as a Double Free vulnerability.
Who is affected by CVE-2026-55995?
CVE-2026-55995 affects users of open-iscsi versions prior to the commit 56718d4e9d1a4f51c30697b5c0534144bb41c9bb.
What impact does CVE-2026-55995 have on systems?
An unauthenticated MITM attacker can exploit CVE-2026-55995 to cause a Denial of Service (DoS) on affected systems.