An update for iscsi-initiator-utils is now available for Red Hat Enterprise
Linux 10.
Red Hat Product Security has rated this update as having a security impact of
Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.
The iscsi-initiator-utils packages provide the server daemon for the Internet
Small Computer System Interface (iSCSI) protocol, as well as the utility programs used to manage it. The iSCSI protocol is a protocol for distributed disk access using SCSI commands sent over Internet Protocol (IP) networks.
Security Fix(es):
* open-iscsi: open-iscsi: Authentication bypass in iscsiuio control socket
(CVE-2026-44944)
* open-iscsi: open-iscsi: Privilege Escalation via Path Traversal
(CVE-2026-44943)
Bug Fix(es) and Enhancement(s):
* [FJ10.1 Bug]: iscsiadm reports node.discovery_type as "fw", although
it should be "static". [rhel-10.2.z] (JIRA:RHEL-191899)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.
CVE-2026-44943: Improper Limitation of a Pathname to a Restricted Directory
('Path Traversal') (CWE-22)
CVE-2026-44944: Insufficient Granularity of Access Control (CWE-1220)
| # | Наименование новости | Тональность | Информативность | Дата публикации |
|---|---|---|---|---|
| 1 | Zwei Probleme in iscsi-initiator-utils (Red Hat) | 0 | 26.67 | 12-08-2026 |
| 2 | Zwei Probleme in openssh (Red Hat) | 0 | 10 | 30-07-2026 |
| 3 | Zwei Probleme in python-pillow (Red Hat) | 0 | 26.67 | 30-07-2026 |
| 4 | Mehrere Probleme in openssh (Red Hat) | 0 | 10 | 30-07-2026 |
| 5 | Zwei Probleme in spice-vdagent (SUSE) | 0 | 30 | 12-08-2026 |
| 6 | Mehrere Probleme in openssh (Slackware) | 0 | 10 | 12-08-2026 |
| 7 | Denial of Service in isns-utils (Red Hat) | 0 | 24.29 | 12-08-2026 |
| 8 | Denial of Service in isns-utils (Red Hat) | 0 | 24.29 | 12-08-2026 |
| 9 | Denial of Service in isns-utils (Red Hat) | 0 | 24.29 | 12-08-2026 |
| 10 | Mehrere Probleme in pcp (SUSE) | 0 | 10 | 13-08-2026 |