Database/Control plane, storage & DevOps
open-iscsi iscsiuio (DHCPv6 handling): Integer underflow and out-of-bounds read in iscsiuio's DHCPv6 handling
Impact
Integer underflow and out-of-bounds read in iscsiuio's DHCPv6 handling. iscsiuio is the userspace daemon that drives iSCSI offload on Broadcom and QLogic adapters, and it processes DHCPv6 from the network to bring up the offload interface — so this is unauthenticated network input reaching a privileged storage daemon. Relevant to GPU clusters that boot or mount datasets over iSCSI, which is still common on the cheaper storage tiers.
Who can reach it
Unauthenticated, adjacent — a rogue DHCPv6 responder on the storage network. DHCPv6 has no authentication and responds fastest-wins, so this needs only presence on the segment.
What to do
Upgrade open-iscsi and restart iscsiuio — package upgrade with a service restart; iSCSI sessions may briefly drop, so drain storage-dependent workloads first. Independently: disable IPv6 on storage networks that do not need it, or enforce DHCPv6 guard on the storage VLAN at the switch, both live config changes.
References
Related entries
- Grafana: injected timeGroup macro in a SQL query exhausts memory and kills the server processCVE-2026-19475 · Grafana SQL data sources (regex macro parsing, timeGroup injected via WHERE clause)Medium
- lldpd (802.1Q VLAN tag stripping in lldpd_decode): lldpd strips 802.1Q VLAN tags by memmove-ing the frame payload fourCVE-2026-46433 · lldpd (802.1Q VLAN tag stripping in lldpd_decode)Medium
- Apache Airflow: Bulk Variables API skips key-based redaction, returning JSON variable secrets in cleartextCVE-2026-48828 · Apache Airflow (Bulk Variables API, secrets masker key-based redaction)Medium
- Apache Airflow: Config API exposes secrets-backend kwargs overrides unmasked, leaking Vault credentialsCVE-2026-48892 · Apache Airflow (Config API, per-key secrets-backend environment overrides)Medium
- Apache Airflow: Dag source endpoint returns the whole file, exposing co-located Dags the caller cannot readCVE-2026-49296 · Apache Airflow (Dag source endpoint, GET /api/v2/dagSources/{dag_id})Medium
- Apache Airflow: task-instance API returns deferred trigger kwargs unmasked, exposing secrets passed to triggersCVE-2026-49487 · Apache Airflow (REST API task-instance endpoints, deferred trigger kwargs)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.