CVE-2026-18728 is a vulnerability in Red Hat Enterprise Linux (RHEL)
Published on August 13, 2026
Open-iscsi: open-iscsi: integer underflow in iscsiuio ipv4 dhcp parsing
A flaw was found in open-iscsi. An integer underflow vulnerability in the `iscsiuio` component, specifically during IPv4 Dynamic Host Configuration Protocol (DHCP) parsing, allows a remote attacker on the same local network segment to cause a denial of service. By sending a specially crafted IPv4/UDP DHCP reply, the attacker can trigger an out-of-bounds read, leading to the `iscsiuio` process crashing. This issue affects systems where `iscsiuio` is actively handling IPv4 DHCP traffic.
Vulnerability Analysis
Timeline
Reported to Red Hat.
Made public. 108 days later.
Weakness Type
What is an Integer underflow Vulnerability?
The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result. This can happen in signed and unsigned cases.
CVE-2026-18728 has been classified to as an Integer underflow vulnerability or weakness.
Products Associated with CVE-2026-18728
Want to know whenever a new CVE is published for Red Hat Enterprise Linux (RHEL)? stack.watch will email you.