GPU VulnDB

Database/Firmware, BMC & network fabric

open-iscsi iscsiuio (DHCPv6 handling): Integer underflow and out-of-bounds read in iscsiuio's DHCPv6 handling

CVE-2026-18727Firmware, BMC & network fabriccurated

Impact

Integer underflow and out-of-bounds read in iscsiuio's DHCPv6 handling. iscsiuio is the userspace daemon that drives iSCSI offload on Broadcom and QLogic adapters, and it processes DHCPv6 from the network to bring up the offload interface — so this is unauthenticated network input reaching a privileged storage daemon. Relevant to GPU clusters that boot or mount datasets over iSCSI, which is still common on the cheaper storage tiers.

Who can reach it

Unauthenticated, adjacent — a rogue DHCPv6 responder on the storage network. DHCPv6 has no authentication and responds fastest-wins, so this needs only presence on the segment.

What to do

Upgrade open-iscsi and restart iscsiuio — package upgrade with a service restart; iSCSI sessions may briefly drop, so drain storage-dependent workloads first. Independently: disable IPv6 on storage networks that do not need it, or enforce DHCPv6 guard on the storage VLAN at the switch, both live config changes.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.