CVE-2026-18726: Loop with Unreachable Exit Condition ('Infinite Loop') in Red Hat Red Hat Enterprise Linux 10
A vulnerability in open-iscsi on Red Hat Enterprise Linux 10 allows a remote attacker on the same local network segment to cause a denial of service in the iscsiuio daemon. By sending a specially crafted ICMPv6 Router Advertisement with a zero-length option, the attacker can trigger an infinite loop, causing sustained CPU usage and making the daemon unresponsive. There is also a secondary risk of out-of-bounds reads with short IPv6 payloads, but no confirmed memory corruption or data exposure. Mitigation involves restricting or filtering ICMPv6 Router Advertisements from untrusted sources or disabling IPv6 Router Advertisement processing on affected interfaces. No official fix or patch is currently confirmed.
AI Analysis
Technical Summary
CVE-2026-18726 is a vulnerability in the open-iscsi component of Red Hat Enterprise Linux 10. It allows a remote attacker on the same Layer 2 network segment to cause a denial of service by sending a crafted ICMPv6 Router Advertisement containing a zero-length option. This triggers an infinite loop in the iscsiuio daemon, resulting in sustained CPU consumption and unresponsiveness of the daemon, impacting system availability. Additionally, there is a secondary risk of out-of-bounds reads with short IPv6 payloads, though no memory corruption or data leakage has been confirmed. The vulnerability requires adjacency on the local network segment and affects IPv6-enabled interfaces handled by iscsiuio. Red Hat advisory recommends mitigation by restricting or filtering ICMPv6 Router Advertisements or disabling their processing on affected interfaces. No official patch or fix has been published yet.
Potential Impact
The vulnerability causes a denial of service by triggering an infinite loop in the iscsiuio daemon, leading to sustained CPU usage and unresponsiveness of the daemon, which impacts system availability. There is no confirmed impact on confidentiality or integrity. The attack requires the attacker to be on the same local network segment and to send specially crafted ICMPv6 Router Advertisements. A secondary risk of out-of-bounds reads exists but no memory corruption or data exposure has been confirmed.
Mitigation Recommendations
Red Hat advises restricting ICMPv6 Router Advertisements from untrusted sources on any network segment where iscsiuio interfaces are exposed. Alternatively, disabling IPv6 Router Advertisement processing on affected interfaces if not operationally required can mitigate the issue. This can be done by configuring firewall rules to filter ICMPv6 type 134 messages or adjusting network interface settings to prevent RA-driven IPv6 configuration. A service restart may be required for changes to take effect. No official patch or fix is currently available; patch status is not yet confirmed — check the Red Hat advisory for updates.
CVE-2026-18726: Loop with Unreachable Exit Condition ('Infinite Loop') in Red Hat Red Hat Enterprise Linux 10
Description
A vulnerability in open-iscsi on Red Hat Enterprise Linux 10 allows a remote attacker on the same local network segment to cause a denial of service in the iscsiuio daemon. By sending a specially crafted ICMPv6 Router Advertisement with a zero-length option, the attacker can trigger an infinite loop, causing sustained CPU usage and making the daemon unresponsive. There is also a secondary risk of out-of-bounds reads with short IPv6 payloads, but no confirmed memory corruption or data exposure. Mitigation involves restricting or filtering ICMPv6 Router Advertisements from untrusted sources or disabling IPv6 Router Advertisement processing on affected interfaces. No official fix or patch is currently confirmed.
CVSS v3.1
Score 6.5medium
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-18726 is a vulnerability in the open-iscsi component of Red Hat Enterprise Linux 10. It allows a remote attacker on the same Layer 2 network segment to cause a denial of service by sending a crafted ICMPv6 Router Advertisement containing a zero-length option. This triggers an infinite loop in the iscsiuio daemon, resulting in sustained CPU consumption and unresponsiveness of the daemon, impacting system availability. Additionally, there is a secondary risk of out-of-bounds reads with short IPv6 payloads, though no memory corruption or data leakage has been confirmed. The vulnerability requires adjacency on the local network segment and affects IPv6-enabled interfaces handled by iscsiuio. Red Hat advisory recommends mitigation by restricting or filtering ICMPv6 Router Advertisements or disabling their processing on affected interfaces. No official patch or fix has been published yet.
Potential Impact
The vulnerability causes a denial of service by triggering an infinite loop in the iscsiuio daemon, leading to sustained CPU usage and unresponsiveness of the daemon, which impacts system availability. There is no confirmed impact on confidentiality or integrity. The attack requires the attacker to be on the same local network segment and to send specially crafted ICMPv6 Router Advertisements. A secondary risk of out-of-bounds reads exists but no memory corruption or data exposure has been confirmed.
Mitigation Recommendations
Red Hat advises restricting ICMPv6 Router Advertisements from untrusted sources on any network segment where iscsiuio interfaces are exposed. Alternatively, disabling IPv6 Router Advertisement processing on affected interfaces if not operationally required can mitigate the issue. This can be done by configuring firewall rules to filter ICMPv6 type 134 messages or adjusting network interface settings to prevent RA-driven IPv6 configuration. A service restart may be required for changes to take effect. No official patch or fix is currently available; patch status is not yet confirmed — check the Red Hat advisory for updates.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- redhat
- Date Reserved
- 2026-08-03T17:55:50.945Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-18726","vendor":"Red Hat"}]
Threat ID: 6a7ce514bf8831d5392fb5c4
Added to database: 08/12/2026, 21:26:44 UTC
Last enriched: 08/12/2026, 21:43:01 UTC
Last updated: 08/13/2026, 03:41:00 UTC
Views: 7
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.