REDHAT-BUG-2508412: High severity open-iscsi vulnerability
Published Jul 29, 2026
·Updated
An Incorrect Authorization vulnerability in open-iscsi allows unprivilidged local users to use the isscsiuio control socket.
This issue affects open-iscsi: from ? through 668ca1df9c9a1e9bdd5c999ae1d67c9c8909237e.
Affected Software
1 affected component
open-iscsi>undefined
Event History
Jul 29, 2026
Data Sourced
via Red Hat·02:01 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
Which environments are exposed to this issue?
Systems running affected open-iscsi versions are exposed when unprivileged local users can access the isscsiuio control socket. The provided information does not indicate a remote attack path.
2
What access does an attacker need?
An attacker needs local, unprivileged user access and the ability to use the isscsiuio control socket. The issue is an authorization failure involving that socket.