RHSA-2026:60333: Important: isns-utils security update
Important: isns-utils security update
Other sources
The iSNS package contains the daemon and tools to setup a iSNS server, and iSNS client tools. The Internet Storage Name Service (iSNS) protocol allows automated discovery, management and configuration of iSCSI and Fibre Channel devices (using iFCP gateways) on a TCP/IP network.Security Fix(es): open-isns: open-iscsi: Denial of Service via double-free in iSNS attribute decoder (CVE-2026-55995) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/isns-utilsto a version that resolves this vulnerability.Fixed in 0.99-1.el8_8.1 - Upgrade
Upgrade
redhat/isns-utils-debuginfoto a version that resolves this vulnerability.Fixed in 0.99-1.el8_8.1 - Upgrade
Upgrade
redhat/isns-utils-debugsourceto a version that resolves this vulnerability.Fixed in 0.99-1.el8_8.1 - Upgrade
Upgrade
redhat/isns-utils-develto a version that resolves this vulnerability.Fixed in 0.99-1.el8_8.1 - Upgrade
Upgrade
redhat/isns-utils-libsto a version that resolves this vulnerability.Fixed in 0.99-1.el8_8.1 - Upgrade
Upgrade
redhat/isns-utils-libs-debuginfoto a version that resolves this vulnerability.Fixed in 0.99-1.el8_8.1 - Upgrade
Upgrade
open-isnsto a version that resolves this vulnerability.Patch CVE-2026-55995 - Upgrade
Upgrade
open-iscsito a version that resolves this vulnerability.Patch CVE-2026-55995
Event History
Frequently Asked Questions
Which systems are most relevant to this update?
Systems running the iSNS daemon or iSNS client tools are most relevant. The affected package set includes isns-utils and its libraries, development, debug, and debuginfo packages on the listed Red Hat Enterprise Linux x86_64 Extended Life Cycle Long Life and Server TUS offerings.
What is the security impact described for this issue?
The issue is a denial of service caused by a double-free in the iSNS attribute decoder. The advisory classifies the update as Important and the provided severity is high.
What configuration or access conditions are required for exploitation?
The provided advisory data does not state the required attacker access, network exposure conditions, or whether a default configuration is affected.