{"id":"SUSE-SU-2026:3647-1","summary":"Security update for open-iscsi","details":"This update for open-iscsi fixes the following issues:\n\n- CVE-2026-44943: remote file-write as root via discovery (bsc#1268353).\n- CVE-2026-44944: iscsiuio control-socket auth bypass (bsc#1268352).\n\nChanges for open-iscsi:\n\n- Update to version 2.1.12.suse+0.8f77cf16:\n * Preparing for version 2.1.12 (#536)\n * iscsi-init.service: Use iscsi-gen-initiatorname\n * iscsi-gen-initiatorname use @IQN_PREFIX@ as default\n * avoid possible double free of found in idbm_rec_update_param (#528)\n * iscsi: validate interface IP against target address family (#527)\n- Update to version 2.1.11.suse+88.8e0635b3:\n * Make iface.example a doc file. (#526)\n * Updated SPEC file to deliver iface.example as a %doc\n file, no longer in the database directory.\n- Update to version 2.1.11.suse+85.4ef97a15:\n * Fix unused variable warning in usr/io.c (#524)\n * Remove old rpm subdirectory, no longer needed.\n * Add tcp.congestion_control configuration option (#520)\n * Small cleanups for firmware discovery. (#522)\n * Fix incorrect parsing of node.discovery_type 'static' and 'fw' (#518)\n * iscsi_net_util: avoid copying NULL pointers with strlcpy() (#515)\n * iscsi: delay reconnect until interface has valid IP. (#511)\n","modified":"2026-08-21T09:15:24.449726611Z","published":"2026-08-19T09:53:51Z","related":["CVE-2026-44943","CVE-2026-44944"],"upstream":["CVE-2026-44943","CVE-2026-44944"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20263647-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268352"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268353"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-44943"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-44944"}],"affected":[{"package":{"name":"open-iscsi","ecosystem":"SUSE:Linux Enterprise Module for Basesystem 15 SP7","purl":"pkg:rpm/suse/open-iscsi&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.1.12-150700.57.6.1"}]}],"ecosystem_specific":{"binaries":[{"libopeniscsiusr0":"0.2.0-150700.57.6.1","open-iscsi":"2.1.12-150700.57.6.1","open-iscsi-devel":"2.1.12-150700.57.6.1","iscsiuio":"0.7.8.8-150700.57.6.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3647-1.json"}}],"schema_version":"1.9.0"}