{"id":"SUSE-SU-2022:2861-1","summary":"Security update for open-iscsi","details":"This update for open-iscsi fixes the following issues:\n\n- CVE-2020-17437: Fixed an out of bounds memory access when the TCP\n  urgent flag is set. (bsc#1179908).\n\nNon-security fixes:\n\n- Fix an issue with ARP booting when using different subnets (bsc#1058463).\n- Allow target discovery using 'db' mode (bsc#1109477).\n","modified":"2026-03-11T07:20:55.310473Z","published":"2022-08-22T08:15:28Z","related":["CVE-2020-17437"],"upstream":["CVE-2020-17437"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2022/suse-su-20222861-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1058463"},{"type":"REPORT","url":"https://bugzilla.suse.com/1109477"},{"type":"REPORT","url":"https://bugzilla.suse.com/1179908"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-17437"}],"affected":[{"package":{"name":"open-iscsi","ecosystem":"SUSE:Linux Enterprise Server 12 SP2-BCL","purl":"pkg:rpm/suse/open-iscsi&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-BCL"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0.873-46.17.2"}]}],"ecosystem_specific":{"binaries":[{"iscsiuio":"0.7.8.2-46.17.2","open-iscsi":"2.0.873-46.17.2","open-isns":"0.95-46.17.2"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:2861-1.json"}}],"schema_version":"1.7.5"}