Skip to main content
EPSS 0.4%top 68%

Red Hat Security Advisory: iscsi-initiator-utils security, bug fix, and enhancement update

0
High
Published: 08/11/2026 (08/11/2026, 21:45:27 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

Two security vulnerabilities have been identified in the iscsi-initiator-utils package used in Red Hat Enterprise Linux 9. These include an authentication bypass in the iscsiuio control socket (CVE-2026-44944) and a privilege escalation via path traversal (CVE-2026-44943). Red Hat has released an update addressing these issues along with bug fixes and enhancements. The vulnerabilities affect multiple architectures including x86_64, s390x, ppc64le, and aarch64. The update is rated as important by Red Hat Product Security.

Affected software

Affected versions
=3.0

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/12/2026, 07:17:33 UTC

Technical Analysis

The iscsi-initiator-utils package provides the server daemon and utilities for managing the iSCSI protocol, which enables distributed disk access over IP networks. Two security flaws were fixed: CVE-2026-44944 involves an authentication bypass vulnerability in the iscsiuio control socket, and CVE-2026-44943 involves privilege escalation through a path traversal vulnerability. These issues could allow unauthorized access or privilege escalation on affected systems. Red Hat issued a security advisory (RHSA-2026:53844) with patches for Red Hat Enterprise Linux 9 across multiple architectures. Additional bug fixes and enhancements were also included in the update.

Potential Impact

Successful exploitation of CVE-2026-44944 could allow an attacker to bypass authentication controls in the iscsiuio control socket, potentially gaining unauthorized access. CVE-2026-44943 could allow privilege escalation via a path traversal attack, enabling an attacker to gain elevated privileges on the system. Both vulnerabilities pose significant security risks to systems running affected versions of iscsi-initiator-utils, potentially compromising system integrity and security.

Mitigation Recommendations

Red Hat has released an official security update for iscsi-initiator-utils in Red Hat Enterprise Linux 9 that addresses these vulnerabilities. Users should apply the update as described in the Red Hat advisory RHSA-2026:53844 to remediate these issues. For detailed instructions, refer to https://access.redhat.com/articles/11258. No additional mitigation steps are indicated beyond applying the official patch.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-36cw-9hwh-mr3c
Osv Schema Version
1.4.0
Aliases
["CVE-2026-44943"]
Database Specific Severity
MODERATE
Cvss Version
4.0

Threat ID: 6a6ae5559c2644c7f899c0d1

Added to database: 07/30/2026, 05:47:01 UTC

Last enriched: 09/12/2026, 07:17:33 UTC

Last updated: 09/12/2026, 22:01:34 UTC

Views: 107

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses