Skip to content
openSUSE open-iscsi Important Local Access Security Update 2026-21580

openSUSE open-iscsi Important Local Access Security Update 2026-21580

Linuxsecurity •LinuxSecurity Advisories • August 16, 2026

Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges ×

This update for open-iscsi fixes the following issues:

Update to version 2.1.12.suse+0.8f77cf16:

- CVE-2026-44943: improper limitation of pathname to a restricted directory allows remote MITM attackers to create

root-owned files outside the database and inject lines into records (bsc#1268353).

- CVE-2026-44944: incorrect authorization allows unpriviledged local users to use the `isscsiuio` control socket

Changes for open-iscsi:

- Version 2.1.12.suse+0.8f77cf16:

* Fix security issues recently discovered by Keith at Linneman Labs.

* iscsi-init.service: use `iscsi-gen-initiatorname`.

* iscsi-gen-initiatorname: use `@IQN_PREFIX@` as default.

* Avoid possible double free of found in `idbm_rec_update_param`.

* iscsi: validate interface IP against target address family.

To install this openSUSE security update use the suse recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the...

- openSUSE Leap 16.0:

iscsiuio-0.7.8.8-160000.4.1

libopeniscsiusr0-0.2.0-160000.4.1

open-iscsi-2.1.12-160000.4.1

open-iscsi-devel-2.1.12-160000.4.1

*

*

Get the latest Linux and open source security news straight to your inbox.