{"id":"CVE-2026-55995","summary":"Double-free in the iSNS attribute decoder in open-iscsi","details":"A Double Free vulnerability in open-iscsi allows an unauthenticated MITM attacker to cause DoS.\n\n\n\n\n\n\nThis issue affects open-iscsi: from ? through 56718d4e9d1a4f51c30697b5c0534144bb41c9bb.","modified":"2026-08-01T08:06:12.275380Z","published":"2026-07-29T13:43:22.381Z","database_specific":{"cna_assigner":"suse","cwe_ids":["CWE-415"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/55xxx/CVE-2026-55995.json","unresolved_ranges":[{"extracted_events":[{"introduced":"?"},{"last_affected":"56718d4e9d1a4f51c30697b5c0534144bb41c9bb"}],"source":"AFFECTED_FIELD"},{"extracted_events":[{"fixed":"56718d4e9d1a4f51c30697b5c0534144bb41c9bb"}],"source":"DESCRIPTION"}]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/55xxx/CVE-2026-55995.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55995"},{"type":"REPORT","url":"https://bugzilla.suse.com/show_bug.cgi?id=CVE-2026-55995"},{"type":"FIX","url":"https://github.com/open-iscsi/open-isns/commit/56718d4e9d1a4f51c30697b5c0534144bb41c9bb"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/open-iscsi/open-isns","events":[{"introduced":"0"},{"fixed":"56718d4e9d1a4f51c30697b5c0534144bb41c9bb"}],"database_specific":{"source":"REFERENCES"}}],"versions":["v0.103","v0.102","v0.101","v0.100","v0.99","v0.97","v0.98","v0.96","v0.95","0.94","0.93"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-55995.json","vanir_signatures_modified":"2026-08-01T08:06:12Z","vanir_signatures":[{"digest":{"function_hash":"337867204291146219561419854160646465349","length":303},"id":"CVE-2026-55995-7773c508","signature_type":"Function","signature_version":"v1","source":"https://github.com/open-iscsi/open-isns/commit/56718d4e9d1a4f51c30697b5c0534144bb41c9bb","target":{"function":"isns_attr_type_string_decode","file":"attrs.c"},"deprecated":false},{"deprecated":false,"digest":{"line_hashes":["181126839560022463853108834279627390706","304264647059442217795861489413632424515","250301943756102260998790019448753689926","279543066480442551210706216074594830461","50594748883323216881980245488699532925","21998209129362232810779321708037676276","176450201884117127306581837101829464371","65418128116049271165254075583321570180"],"threshold":0.9},"id":"CVE-2026-55995-b03e2d8c","signature_type":"Line","signature_version":"v1","source":"https://github.com/open-iscsi/open-isns/commit/56718d4e9d1a4f51c30697b5c0534144bb41c9bb","target":{"file":"attrs.c"}},{"target":{"file":"attrs.c","function":"isns_attr_type_opaque_decode"},"deprecated":false,"digest":{"function_hash":"326105002302471803800672137860604776505","length":287},"id":"CVE-2026-55995-e150ede7","signature_type":"Function","signature_version":"v1","source":"https://github.com/open-iscsi/open-isns/commit/56718d4e9d1a4f51c30697b5c0534144bb41c9bb"}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}]}