RHSA-2026:60005: Important: isns-utils security update
The iSNS package contains the daemon and tools to setup a iSNS server, and iSNS client tools. The Internet Storage Name Service (iSNS) protocol allows automated discovery, management and configuration of iSCSI and Fibre Channel devices (using iFCP gateways) on a TCP/IP network.Security Fix(es): open-isns: open-iscsi: Denial of Service via double-free in iSNS attribute decoder (CVE-2026-55995) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/isns-utilsto a version that resolves this vulnerability.Fixed in 0.103-1.el10_0.1 - Upgrade
Upgrade
redhat/isns-utils-debuginfoto a version that resolves this vulnerability.Fixed in 0.103-1.el10_0.1 - Upgrade
Upgrade
redhat/isns-utils-debugsourceto a version that resolves this vulnerability.Fixed in 0.103-1.el10_0.1 - Upgrade
Upgrade
redhat/isns-utils-libsto a version that resolves this vulnerability.Fixed in 0.103-1.el10_0.1 - Upgrade
Upgrade
redhat/isns-utils-libs-debuginfoto a version that resolves this vulnerability.Fixed in 0.103-1.el10_0.1 - Upgrade
Upgrade
redhat/isns-utilsto a version that resolves this vulnerability.Fixed in 0.103-1.el10_0.1.aa - Upgrade
Upgrade
redhat/isns-utils-debuginfoto a version that resolves this vulnerability.Fixed in 0.103-1.el10_0.1.aa - Upgrade
Upgrade
redhat/isns-utils-debugsourceto a version that resolves this vulnerability.Fixed in 0.103-1.el10_0.1.aa - Upgrade
Upgrade
redhat/isns-utils-libsto a version that resolves this vulnerability.Fixed in 0.103-1.el10_0.1.aa - Upgrade
Upgrade
redhat/isns-utils-libs-debuginfoto a version that resolves this vulnerability.Fixed in 0.103-1.el10_0.1.aa - Upgrade
Upgrade
open-isns / open-iscsi (iSNS)to a version that resolves this vulnerability.Patch CVE-2026-55995
Event History
Frequently Asked Questions
Which systems are most relevant to this update?
Systems using the iSNS daemon or client tools for discovery, management, or configuration of iSCSI devices or Fibre Channel devices through iFCP gateways are the relevant exposure set. The affected update includes isns-utils and its associated libraries, debug packages, and debuginfo packages.
What is the documented impact of the flaw?
The issue is a denial of service caused by a double-free condition in the iSNS attribute decoder. The advisory identifies it as CVE-2026-55995 and classifies the update as Important.