RHSA-2026:53846: Important: isns-utils security update
Important: isns-utils security update
Other sources
The iSNS package contains the daemon and tools to setup a iSNS server, and iSNS client tools. The Internet Storage Name Service (iSNS) protocol allows automated discovery, management and configuration of iSCSI and Fibre Channel devices (using iFCP gateways) on a TCP/IP network.Security Fix(es): open-isns: open-iscsi: Denial of Service via double-free in iSNS attribute decoder (CVE-2026-55995) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/isns-utilsto a version that resolves this vulnerability.Fixed in 0.103-1.el10_2.1 - Upgrade
Upgrade
redhat/isns-utils-debuginfoto a version that resolves this vulnerability.Fixed in 0.103-1.el10_2.1 - Upgrade
Upgrade
redhat/isns-utils-debugsourceto a version that resolves this vulnerability.Fixed in 0.103-1.el10_2.1 - Upgrade
Upgrade
redhat/isns-utils-libsto a version that resolves this vulnerability.Fixed in 0.103-1.el10_2.1 - Upgrade
Upgrade
redhat/isns-utils-libs-debuginfoto a version that resolves this vulnerability.Fixed in 0.103-1.el10_2.1 - Upgrade
Upgrade
redhat/isns-utilsto a version that resolves this vulnerability.Fixed in 0.103-1.el10_2.1.aa - Upgrade
Upgrade
redhat/isns-utils-debuginfoto a version that resolves this vulnerability.Fixed in 0.103-1.el10_2.1.aa - Upgrade
Upgrade
redhat/isns-utils-debugsourceto a version that resolves this vulnerability.Fixed in 0.103-1.el10_2.1.aa - Upgrade
Upgrade
redhat/isns-utils-libsto a version that resolves this vulnerability.Fixed in 0.103-1.el10_2.1.aa - Upgrade
Upgrade
redhat/isns-utils-libs-debuginfoto a version that resolves this vulnerability.Fixed in 0.103-1.el10_2.1.aa
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:53846?
The severity of RHSA-2026:53846 is classified as high with a CVSS score of 7.
What is the main purpose of the isns-utils package in RHSA-2026:53846?
The isns-utils package facilitates the setup and management of iSNS servers and client tools for iSCSI and Fibre Channel devices.
How do I fix the vulnerability mentioned in RHSA-2026:53846?
To fix the vulnerability in RHSA-2026:53846, update the isns-utils package and its related components to the latest version provided by Red Hat.
What systems are affected by RHSA-2026:53846?
The affected systems include Red Hat Enterprise Linux for ARM 64, x86_64, and Power architectures.
Is there a security update available for RHSA-2026:53846?
Yes, a security update is available for RHSA-2026:53846 to address the identified vulnerabilities in the isns-utils package.