{"id":"AZL-95919","summary":"CVE-2026-18728 affecting package iscsi-initiator-utils 2.1.12-1","details":"A flaw was found in open-iscsi. An integer underflow vulnerability in the `iscsiuio` component, specifically during IPv4 Dynamic Host Configuration Protocol (DHCP) parsing, allows a remote attacker on the same local network segment to cause a denial of service. By sending a specially crafted IPv4/UDP DHCP reply, the attacker can trigger an out-of-bounds read, leading to the `iscsiuio` process crashing. This issue affects systems where `iscsiuio` is actively handling IPv4 DHCP traffic.","modified":"2026-08-31T05:26:27Z","published":"2026-08-13T04:17:19Z","upstream":["CVE-2026-18728"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-18728"}],"affected":[{"package":{"name":"iscsi-initiator-utils","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/iscsi-initiator-utils"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"2.1.12-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-95919.json"}}],"schema_version":"1.9.0"}