REDHAT-BUG-2508414: Double Free
Published Jul 29, 2026
·Updated
A Double Free vulnerability in open-iscsi allows an unauthenticated MITM attacker to cause DoS.
This issue affects open-iscsi: from ? through 56718d4e9d1a4f51c30697b5c0534144bb41c9bb.
Affected Software
1 affected component
open-iscsi<=56718d4e9d1a4f51c30697b5c0534144bb41c9bb
Event History
Jul 29, 2026
Data Sourced
via Red Hat·02:02 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
Who can realistically exploit this issue?
Systems running affected open-iscsi versions are exposed when an unauthenticated attacker can position themselves as a man-in-the-middle for relevant traffic. The stated impact is denial of service.
2
How can I determine whether my deployment is affected?
The affected range is stated only as beginning at an unspecified version and ending at commit 56718d4e9d1a4f51c30697b5c0534144bb41c9bb. Check the open-iscsi version or source revision deployed in your environment against vendor errata RHSA-2026:53846 and RHSA-2026:53847.