RHSA-2026:61249: Important: isns-utils security update
Important: isns-utils security update
Other sources
The iSNS package contains the daemon and tools to setup a iSNS server, and iSNS client tools. The Internet Storage Name Service (iSNS) protocol allows automated discovery, management and configuration of iSCSI and Fibre Channel devices (using iFCP gateways) on a TCP/IP network.Security Fix(es): open-isns: open-iscsi: Denial of Service via double-free in iSNS attribute decoder (CVE-2026-55995) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/isns-utilsto a version that resolves this vulnerability.Fixed in 0.99-1.el8_4.1 - Upgrade
Upgrade
redhat/isns-utils-debuginfoto a version that resolves this vulnerability.Fixed in 0.99-1.el8_4.1 - Upgrade
Upgrade
redhat/isns-utils-debugsourceto a version that resolves this vulnerability.Fixed in 0.99-1.el8_4.1 - Upgrade
Upgrade
redhat/isns-utils-develto a version that resolves this vulnerability.Fixed in 0.99-1.el8_4.1 - Upgrade
Upgrade
redhat/isns-utils-libsto a version that resolves this vulnerability.Fixed in 0.99-1.el8_4.1 - Upgrade
Upgrade
redhat/isns-utils-libs-debuginfoto a version that resolves this vulnerability.Fixed in 0.99-1.el8_4.1 - Upgrade
Upgrade
open-isns / open-iscsi (iSNS)to a version that resolves this vulnerability.Patch CVE-2026-55995
Event History
Frequently Asked Questions
Which package components are included in this update?
The advisory lists isns-utils, isns-utils-libs, isns-utils-devel, and their debuginfo and debugsource packages.
Which Red Hat product channels are named in the advisory?
The listed channels are Red Hat Enterprise Linux for x86_64 Extended Life Cycle Long Life and Red Hat Enterprise Linux Server AUS.