RHSA-2026:53844HighCVSS 8.6

Red Hat Security Advisory: iscsi-initiator-utils security, bug fix, and enhancement update

Published
August 11, 2026
Last Modified
August 26, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2026-44943 — open-iscsi: open-iscsi: Privilege Escalation via Path Traversal CVE-2026-44944 — open-iscsi: open-iscsi: Authentication bypass in iscsiuio control socket

🎯 Affected products52

  • Red Hat Enterprise Linux AppStream (v. 9)
  • Red Hat Enterprise Linux BaseOS (v. 9)
  • iscsi-initiator-utils-0:6.2.1.11-1.git4b3e853.el9_8.2.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
  • iscsi-initiator-utils-0:6.2.1.11-1.git4b3e853.el9_8.2.i686 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
  • iscsi-initiator-utils-0:6.2.1.11-1.git4b3e853.el9_8.2.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 9)
  • iscsi-initiator-utils-0:6.2.1.11-1.git4b3e853.el9_8.2.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 9)
  • iscsi-initiator-utils-0:6.2.1.11-1.git4b3e853.el9_8.2.src as a component of Red Hat Enterprise Linux BaseOS (v. 9)
  • iscsi-initiator-utils-0:6.2.1.11-1.git4b3e853.el9_8.2.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
  • iscsi-initiator-utils-debuginfo-0:6.2.1.11-1.git4b3e853.el9_8.2.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • iscsi-initiator-utils-debuginfo-0:6.2.1.11-1.git4b3e853.el9_8.2.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
  • iscsi-initiator-utils-debuginfo-0:6.2.1.11-1.git4b3e853.el9_8.2.i686 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
  • iscsi-initiator-utils-debuginfo-0:6.2.1.11-1.git4b3e853.el9_8.2.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • iscsi-initiator-utils-debuginfo-0:6.2.1.11-1.git4b3e853.el9_8.2.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 9)
  • iscsi-initiator-utils-debuginfo-0:6.2.1.11-1.git4b3e853.el9_8.2.s390x as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • iscsi-initiator-utils-debuginfo-0:6.2.1.11-1.git4b3e853.el9_8.2.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 9)
  • iscsi-initiator-utils-debuginfo-0:6.2.1.11-1.git4b3e853.el9_8.2.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • iscsi-initiator-utils-debuginfo-0:6.2.1.11-1.git4b3e853.el9_8.2.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
  • iscsi-initiator-utils-debugsource-0:6.2.1.11-1.git4b3e853.el9_8.2.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • iscsi-initiator-utils-debugsource-0:6.2.1.11-1.git4b3e853.el9_8.2.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
  • iscsi-initiator-utils-debugsource-0:6.2.1.11-1.git4b3e853.el9_8.2.i686 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
  • iscsi-initiator-utils-debugsource-0:6.2.1.11-1.git4b3e853.el9_8.2.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • iscsi-initiator-utils-debugsource-0:6.2.1.11-1.git4b3e853.el9_8.2.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 9)
  • iscsi-initiator-utils-debugsource-0:6.2.1.11-1.git4b3e853.el9_8.2.s390x as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • iscsi-initiator-utils-debugsource-0:6.2.1.11-1.git4b3e853.el9_8.2.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 9)
  • iscsi-initiator-utils-debugsource-0:6.2.1.11-1.git4b3e853.el9_8.2.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • iscsi-initiator-utils-debugsource-0:6.2.1.11-1.git4b3e853.el9_8.2.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
  • iscsi-initiator-utils-iscsiuio-0:6.2.1.11-1.git4b3e853.el9_8.2.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
  • iscsi-initiator-utils-iscsiuio-0:6.2.1.11-1.git4b3e853.el9_8.2.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 9)
  • iscsi-initiator-utils-iscsiuio-0:6.2.1.11-1.git4b3e853.el9_8.2.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 9)
  • iscsi-initiator-utils-iscsiuio-0:6.2.1.11-1.git4b3e853.el9_8.2.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
  • +22 more not shown

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: To mitigate this issue, restrict network access to iSCSI initiator systems to only trusted networks and hosts. If iSCSI is not actively used, consider disabling the `iscsid` service to prevent potential exploitation. To disable the `iscsid` service: `systemctl stop iscsid` `systemctl disable iscsid` *Note that disabling the iSCSI service will prevent the system from connecting to iSCSI targets and may impact functionality. Workaround: If iSCSI offload engine functionality is not required, the `iscsiuio` service can be disabled to prevent exploitation. This action will stop the service immediately and prevent it from starting on subsequent reboots. To disable the `iscsiuio` service: ```bash sudo systemctl disable --now iscsiuio.service sudo systemctl mask iscsiuio.service ``` *Disabling this service will impact any systems relying on iSCSI offload engines. A system restart or service reload may be required for the changes to take full effect.

🔗 References (5)