{"id":"AZL-95925","summary":"CVE-2026-18726 affecting package iscsi-initiator-utils 2.1.12-1","details":"A flaw was found in open-iscsi. This vulnerability allows a remote attacker on the same local network segment to cause a Denial of Service (DoS) in the iscsiuio daemon. By sending a specially crafted Internet Control Message Protocol version 6 (ICMPv6) Router Advertisement with a zero-length option, the attacker can trigger an infinite loop. This leads to sustained CPU usage, rendering the daemon unresponsive and impacting system availability. A secondary risk of out-of-bounds reads exists with a short IPv6 payload, though no memory corruption or data exposure has been confirmed.","modified":"2026-08-31T05:26:27Z","published":"2026-08-12T22:17:14Z","upstream":["CVE-2026-18726"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-18726"}],"affected":[{"package":{"name":"iscsi-initiator-utils","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/iscsi-initiator-utils"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"2.1.12-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-95925.json"}}],"schema_version":"1.9.0"}