RHSA-2026:53848: Important: isns-utils security update
Important: isns-utils security update
Other sources
The iSNS package contains the daemon and tools to setup a iSNS server, and iSNS client tools. The Internet Storage Name Service (iSNS) protocol allows automated discovery, management and configuration of iSCSI and Fibre Channel devices (using iFCP gateways) on a TCP/IP network.Security Fix(es): open-isns: open-iscsi: Denial of Service via double-free in iSNS attribute decoder (CVE-2026-55995) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/isns-utilsto a version that resolves this vulnerability.Fixed in 0.99-1.el8_10.1 - Upgrade
Upgrade
redhat/isns-utils-debuginfoto a version that resolves this vulnerability.Fixed in 0.99-1.el8_10.1 - Upgrade
Upgrade
redhat/isns-utils-debugsourceto a version that resolves this vulnerability.Fixed in 0.99-1.el8_10.1 - Upgrade
Upgrade
redhat/isns-utils-develto a version that resolves this vulnerability.Fixed in 0.99-1.el8_10.1 - Upgrade
Upgrade
redhat/isns-utils-libsto a version that resolves this vulnerability.Fixed in 0.99-1.el8_10.1 - Upgrade
Upgrade
redhat/isns-utils-libs-debuginfoto a version that resolves this vulnerability.Fixed in 0.99-1.el8_10.1 - Upgrade
Upgrade
redhat/isns-utilsto a version that resolves this vulnerability.Fixed in 0.99-1.el8_10.1.aa - Upgrade
Upgrade
redhat/isns-utils-debuginfoto a version that resolves this vulnerability.Fixed in 0.99-1.el8_10.1.aa - Upgrade
Upgrade
redhat/isns-utils-debugsourceto a version that resolves this vulnerability.Fixed in 0.99-1.el8_10.1.aa - Upgrade
Upgrade
redhat/isns-utils-develto a version that resolves this vulnerability.Fixed in 0.99-1.el8_10.1.aa - Upgrade
Upgrade
redhat/isns-utils-libsto a version that resolves this vulnerability.Fixed in 0.99-1.el8_10.1.aa - Upgrade
Upgrade
redhat/isns-utils-libs-debuginfoto a version that resolves this vulnerability.Fixed in 0.99-1.el8_10.1.aa
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:53848?
The severity of RHSA-2026:53848 is classified as high with a score of 7.
What vulnerabilities does RHSA-2026:53848 address?
RHSA-2026:53848 addresses vulnerabilities within the iSNS package, which includes tools for managing iSCSI and Fibre Channel devices.
How do I resolve the vulnerabilities associated with RHSA-2026:53848?
To resolve the vulnerabilities of RHSA-2026:53848, update to the latest version of the isns-utils package.
What systems are affected by RHSA-2026:53848?
Affected systems include various versions of Red Hat Enterprise Linux, such as ARM 64 and Power, little endian.
Is the iSNS package critical for my Red Hat system?
Yes, the iSNS package is critical for facilitating automated discovery and management of storage devices in Red Hat systems.