RHSA-2026:60385: Important: isns-utils security update
Important: isns-utils security update
Other sources
The iSNS package contains the daemon and tools to setup a iSNS server, and iSNS client tools. The Internet Storage Name Service (iSNS) protocol allows automated discovery, management and configuration of iSCSI and Fibre Channel devices (using iFCP gateways) on a TCP/IP network.Security Fix(es): open-isns: open-iscsi: Denial of Service via double-free in iSNS attribute decoder (CVE-2026-55995) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/isns-utilsto a version that resolves this vulnerability.Fixed in 0.99-1.el8_6.1 - Upgrade
Upgrade
redhat/isns-utils-debuginfoto a version that resolves this vulnerability.Fixed in 0.99-1.el8_6.1 - Upgrade
Upgrade
redhat/isns-utils-debugsourceto a version that resolves this vulnerability.Fixed in 0.99-1.el8_6.1 - Upgrade
Upgrade
redhat/isns-utils-develto a version that resolves this vulnerability.Fixed in 0.99-1.el8_6.1 - Upgrade
Upgrade
redhat/isns-utils-libsto a version that resolves this vulnerability.Fixed in 0.99-1.el8_6.1 - Upgrade
Upgrade
redhat/isns-utils-libs-debuginfoto a version that resolves this vulnerability.Fixed in 0.99-1.el8_6.1
Event History
Frequently Asked Questions
Which deployments should assess this update first?
Assess systems running the iSNS daemon or iSNS client tools, particularly where iSNS is used for discovery, management, or configuration of iSCSI devices or Fibre Channel devices through iFCP gateways on a TCP/IP network.
Are non-runtime package variants included in the advisory?
Yes. The listed affected software includes isns-utils-devel, isns-utils-debuginfo, isns-utils-debugsource, isns-utils-libs, and isns-utils-libs-debuginfo in addition to the main isns-utils package.