Critical Vulnerabilities in open-iscsi Affecting SUSE and openSUSE Systems

Critical Vulnerabilities in open-iscsi Affecting SUSE and openSUSE Systems

First seen 18 Aug 2026, 08:36 UTC Linuxsecurity 94% similarity 70.5

Article Content

Browse articles
ThreatCluster

SUSE has released an important update for open-iscsi to address two critical vulnerabilities, CVE-2026-44943 and CVE-2026-44944, both published on 2026-07-29. CVE-2026-44943 allows remote MITM attackers to create root-owned files outside the database due to improper pathname limitations. CVE-2026-44944 permits unprivileged local users to access the `isscsiuio` control socket due to incorrect authorization. The vulnerabilities affect systems running open-iscsi version 2.1.12.suse+0.8f77cf16. Users are advised to audit Linux privileges to limit potential compromises. The update is critical for maintaining system integrity and security. The vulnerabilities were discovered by Keith at Linneman Labs, highlighting the importance of timely updates.

Key Points: • Two critical vulnerabilities in open-iscsi affect SUSE and openSUSE systems. • CVE-2026-44943 allows remote attackers to create unauthorized root-owned files. • CVE-2026-44944 enables local users to exploit control socket access improperly.

ThreatCluster AI How this analysis works

Timeline

2026-07-29
CVE-2026-44943 published
SUSE disclosed a vulnerability allowing remote attackers to create unauthorized root-owned files.
Linuxsecurity
2026-07-29
CVE-2026-44944 published
SUSE reported a vulnerability that allows unprivileged local users to access the `isscsiuio` control socket.
Linuxsecurity
2026-08-14
SUSE releases important update for open-iscsi
An update was released to fix the vulnerabilities in open-iscsi version 2.1.12.suse+0.8f77cf16, addressing both CVEs.
Linuxsecurity
2026-08-16
openSUSE issues local access security update
openSUSE announced a security update for open-iscsi, emphasizing the need for immediate action to mitigate risks.
Linuxsecurity

Community

Browse all →

Tracked Entities in This Story