Linuxsecurity Critical Vulnerabilities in open-iscsi Affecting SUSE and openSUSE Systems
Article Content
- •Two critical vulnerabilities in open-iscsi affect SUSE and openSUSE systems.
- •CVE-2026-44943 allows remote attackers to create unauthorized root-owned files.
- •CVE-2026-44944 enables local users to exploit control socket access improperly.
SUSE has released an important update for open-iscsi to address two critical vulnerabilities, CVE-2026-44943 and CVE-2026-44944, both published on 2026-07-29. CVE-2026-44943 allows remote MITM attackers to create root-owned files outside the database due to improper pathname limitations. CVE-2026-44944 permits unprivileged local users to access the `isscsiuio` control socket due to incorrect authorization. The vulnerabilities affect systems running open-iscsi version 2.1.12.suse+0.8f77cf16. Users are advised to audit Linux privileges to limit potential compromises. The update is critical for maintaining system integrity and security. The vulnerabilities were discovered by Keith at Linneman Labs, highlighting the importance of timely updates.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track CVE-2026-44943 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited In late September 2026, two critical zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in Citrix NetScaler ADC and Gateway were actively exploited, allowing remote code execution. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on…
Critical Citrix NetScaler Vulnerabilities Actively Exploited in Finland The National Cyber Security Centre Finland (NCSC-FI) issued an alert regarding critical vulnerabilities in Citrix NetScaler ADC and Gateway products, specifically CVE-2026-88771 and CVE-2026-88772, which are being actively exploited in Finland. These vulnerabilities allow attackers to execute remote code without…