CVE-2026-18728: Integer Underflow (Wrap or Wraparound) in Red Hat Red Hat Enterprise Linux 10
An integer underflow vulnerability exists in the iscsiuio component of open-iscsi on Red Hat Enterprise Linux 10, specifically during IPv4 DHCP parsing. A remote attacker on the same local network segment can send a crafted IPv4/UDP DHCP reply to trigger an out-of-bounds read, causing the iscsiuio process to crash and resulting in a denial of service. This issue requires iscsiuio to be actively handling IPv4 DHCP traffic and specific network conditions to be exploitable.
AI Analysis
Technical Summary
CVE-2026-18728 is an integer underflow vulnerability in the iscsiuio component of open-iscsi on Red Hat Enterprise Linux 10. The flaw occurs during IPv4 DHCP parsing, where a specially crafted IPv4/UDP DHCP reply can cause an out-of-bounds read, crashing the iscsiuio process and causing a denial of service. Exploitation requires an attacker to be on the same local network segment and iscsiuio to be configured to use IPv4 DHCP. The vulnerability is rated moderate severity with a CVSS 3.1 score of 6.5 (AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
Potential Impact
The vulnerability allows a remote attacker on the same local network segment to cause a denial of service by crashing the iscsiuio process through an out-of-bounds read triggered by a crafted DHCP reply. There is no impact on confidentiality or integrity. Exploitation requires specific network conditions and configuration, limiting broader impact.
Mitigation Recommendations
No official patch or fix is currently confirmed. To mitigate this issue, restrict network access to interfaces managed by iscsiuio. Configure firewall rules to limit DHCP/BOOTP traffic to trusted infrastructure within the local broadcast domain. Consider reconfiguring iscsiuio to use static IP addresses or alternative network configurations if feasible. Changes to network configuration may require restarting the iscsiuio service. Monitor the Red Hat advisory for updates on patch availability.
CVE-2026-18728: Integer Underflow (Wrap or Wraparound) in Red Hat Red Hat Enterprise Linux 10
Description
An integer underflow vulnerability exists in the iscsiuio component of open-iscsi on Red Hat Enterprise Linux 10, specifically during IPv4 DHCP parsing. A remote attacker on the same local network segment can send a crafted IPv4/UDP DHCP reply to trigger an out-of-bounds read, causing the iscsiuio process to crash and resulting in a denial of service. This issue requires iscsiuio to be actively handling IPv4 DHCP traffic and specific network conditions to be exploitable.
CVSS v3.1
Score 6.5medium
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-18728 is an integer underflow vulnerability in the iscsiuio component of open-iscsi on Red Hat Enterprise Linux 10. The flaw occurs during IPv4 DHCP parsing, where a specially crafted IPv4/UDP DHCP reply can cause an out-of-bounds read, crashing the iscsiuio process and causing a denial of service. Exploitation requires an attacker to be on the same local network segment and iscsiuio to be configured to use IPv4 DHCP. The vulnerability is rated moderate severity with a CVSS 3.1 score of 6.5 (AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
Potential Impact
The vulnerability allows a remote attacker on the same local network segment to cause a denial of service by crashing the iscsiuio process through an out-of-bounds read triggered by a crafted DHCP reply. There is no impact on confidentiality or integrity. Exploitation requires specific network conditions and configuration, limiting broader impact.
Mitigation Recommendations
No official patch or fix is currently confirmed. To mitigate this issue, restrict network access to interfaces managed by iscsiuio. Configure firewall rules to limit DHCP/BOOTP traffic to trusted infrastructure within the local broadcast domain. Consider reconfiguring iscsiuio to use static IP addresses or alternative network configurations if feasible. Changes to network configuration may require restarting the iscsiuio service. Monitor the Red Hat advisory for updates on patch availability.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- redhat
- Date Reserved
- 2026-08-03T17:55:57.114Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-18728","vendor":"Red Hat"}]
Threat ID: 6a7d3d04bf8831d5399c8e47
Added to database: 08/13/2026, 03:41:56 UTC
Last enriched: 08/13/2026, 04:00:15 UTC
Last updated: 08/13/2026, 04:01:01 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.