RHSA-2026:60427: Important: iscsi-initiator-utils security update
Important: iscsi-initiator-utils security update
Other sources
The iscsi-initiator-utils packages provide the server daemon for the Internet Small Computer System Interface (iSCSI) protocol, as well as the utility programs used to manage it. The iSCSI protocol is a protocol for distributed disk access using SCSI commands sent over Internet Protocol (IP) networks.Security Fix(es): open-iscsi: open-iscsi: Authentication bypass in iscsiuio control socket (CVE-2026-44944) open-iscsi: open-iscsi: Privilege Escalation via Path Traversal (CVE-2026-44943) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/iscsi-initiator-utilsto a version that resolves this vulnerability.Fixed in 6.2.1.9-1.gita65a472.el9_4.2 - Upgrade
Upgrade
redhat/iscsi-initiator-utils-debuginfoto a version that resolves this vulnerability.Fixed in 6.2.1.9-1.gita65a472.el9_4.2 - Upgrade
Upgrade
redhat/iscsi-initiator-utils-debugsourceto a version that resolves this vulnerability.Fixed in 6.2.1.9-1.gita65a472.el9_4.2 - Upgrade
Upgrade
redhat/iscsi-initiator-utils-iscsiuioto a version that resolves this vulnerability.Fixed in 6.2.1.9-1.gita65a472.el9_4.2 - Upgrade
Upgrade
redhat/iscsi-initiator-utils-iscsiuio-debuginfoto a version that resolves this vulnerability.Fixed in 6.2.1.9-1.gita65a472.el9_4.2 - Upgrade
Upgrade
redhat/python3-iscsi-initiator-utilsto a version that resolves this vulnerability.Fixed in 6.2.1.9-1.gita65a472.el9_4.2 - Upgrade
Upgrade
redhat/python3-iscsi-initiator-utils-debuginfoto a version that resolves this vulnerability.Fixed in 6.2.1.9-1.gita65a472.el9_4.2 - Upgrade
Upgrade
redhat/iscsi-initiator-utilsto a version that resolves this vulnerability.Fixed in 6.2.1.9-1.gita65a472.el9_4.2.aa - Upgrade
Upgrade
redhat/iscsi-initiator-utils-debuginfoto a version that resolves this vulnerability.Fixed in 6.2.1.9-1.gita65a472.el9_4.2.aa - Upgrade
Upgrade
redhat/iscsi-initiator-utils-debugsourceto a version that resolves this vulnerability.Fixed in 6.2.1.9-1.gita65a472.el9_4.2.aa - Upgrade
Upgrade
redhat/iscsi-initiator-utils-iscsiuioto a version that resolves this vulnerability.Fixed in 6.2.1.9-1.gita65a472.el9_4.2.aa - Upgrade
Upgrade
redhat/iscsi-initiator-utils-iscsiuio-debuginfoto a version that resolves this vulnerability.Fixed in 6.2.1.9-1.gita65a472.el9_4.2.aa - Upgrade
Upgrade
redhat/python3-iscsi-initiator-utilsto a version that resolves this vulnerability.Fixed in 6.2.1.9-1.gita65a472.el9_4.2.aa - Upgrade
Upgrade
redhat/python3-iscsi-initiator-utils-debuginfoto a version that resolves this vulnerability.Fixed in 6.2.1.9-1.gita65a472.el9_4.2.aa
Event History
Frequently Asked Questions
Which installed components should be included when assessing exposure to this update?
Review installations of iscsi-initiator-utils and its iscsiuio component, including the python3-iscsi-initiator-utils package where present. The advisory also lists associated debuginfo and debugsource packages.
What types of issues are addressed by this update?
The update addresses an authentication bypass in the iscsiuio control socket (CVE-2026-44944) and a privilege-escalation issue involving path traversal (CVE-2026-44943).