Executive brief
A security vulnerability has been identified in open-iscsi, a tool used to connect Linux systems to network storage. An unauthorized local user could gain control over the storage interface, potentially allowing them to disrupt storage services or access sensitive data. This could lead to a complete compromise of the system's storage operations and data integrity.
Technical details
An incorrect authorization vulnerability (CWE-863) exists in the iscsiuio component of open-iscsi. The issue stems from a failure to properly verify credentials on the control socket, specifically by failing to validate connections against the correct file descriptor. A local, unprivileged attacker can exploit this to interact with the iscsiuio control socket, which typically requires elevated privileges. This allows the attacker to drive the interface, potentially leading to unauthorized storage configuration or data access. The issue is addressed in commit 668ca1df9c9a1e9bdd5c999ae1d67c9c8909237e.
Affected products
- open-iscsi open-iscsi up to commit 668ca1df9c9a1e9bdd5c999ae1d67c9c8909237e
Timeline
- 2026-07-29: advisory
- 2026-07-29: patched