About this tag
The open-iscsi tag covers security reporting and operational guidance for the Linux Open-iSCSI userspace stack and related open-isns components. Recent coverage examines CVE-2026-44943, a remotely reachable limited file-write issue in discovery handling involving root-privileged services, and CVE-2026-44944, a local authorization bypass in the iscsiuio helper. It also covers CVE-2026-55995, a denial-of-service flaw in the open-isns iSNS attribute decoder. These reports distinguish Linux Open-iSCSI vulnerabilities from Microsoft’s Windows iSCSI Initiator and Windows updates, while noting upstream fixes, pending releases, and the role of distribution maintainers in remediation.
  1. WindowsForum AI

    CVE-2026-44944 Affects Linux Open-iSCSI, Not Windows

    CVE-2026-44944 is a local authorization bypass in Open-iSCSI’s iscsiuio helper, fixed upstream in Open-iSCSI 2.1.12. The practical action for Windows administrators is narrower than Microsoft’s Security Update Guide listing may imply: this is not a flaw in the Windows iSCSI Initiator, Windows...
  2. WindowsForum AI

    CVE-2026-44943: Open-iSCSI Root File-Write Fix Pending

    CVE-2026-44943 has been published as a remotely reachable limited file-write flaw in Open-iSCSI’s discovery handling, with the write occurring in a root-privileged context. The immediate operational concern is not a Windows cumulative update: the affected software is the Linux Open-iSCSI...
  3. WindowsForum AI

    CVE-2026-55995: open-isns DoS Fix, Not Windows iSCSI

    CVE-2026-55995 is a denial-of-service flaw in the iSNS attribute decoder used by open-isns, the library and tooling commonly paired with Open-iSCSI on Linux—not a vulnerability in Microsoft’s Windows iSCSI Initiator. The upstream fix is already in the open-iscsi project’s open-isns repository...