{"id":"SUSE-SU-2022:2806-1","summary":"Security update for open-iscsi","details":"This update for open-iscsi fixes the following issues:\n\nFixed various vulnerabilities in the embedded TCP/IP stack (bsc#1179908):\n - CVE-2020-13987: Fixed an out of bounds memory access when\n   calculating the checksums for IP packets.\n - CVE-2020-13988: Fixed an integer overflow when parsing TCP MSS\n   options of IPv4 network packets.\n - CVE-2020-17437: Fixed an out of bounds memory access when the TCP\n   urgent flag is set.\n","modified":"2026-03-11T07:20:36.641072Z","published":"2022-08-15T08:01:18Z","related":["CVE-2020-13987","CVE-2020-13988","CVE-2020-17437"],"upstream":["CVE-2020-13987","CVE-2020-13988","CVE-2020-17437"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2022/suse-su-20222806-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1179908"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-13987"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-13988"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-17437"}],"affected":[{"package":{"name":"open-iscsi","ecosystem":"SUSE:Linux Enterprise Server 12 SP3-BCL","purl":"pkg:rpm/suse/open-iscsi&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3-BCL"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0.876-53.34.1"}]}],"ecosystem_specific":{"binaries":[{"iscsiuio":"0.7.8.2-53.34.1","libopeniscsiusr0_2_0":"2.0.876-53.34.1","open-iscsi":"2.0.876-53.34.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:2806-1.json"}}],"schema_version":"1.7.5"}