What is CVE-2026-55995?
CVE-2026-55995 is a Double Free vulnerability in open-iscsi that allows an unauthenticated MITM attacker to cause a Denial of Service (DoS). Affected versions should be updated to the commit 56718d4e9d1a4f51c30697b5c0534144bb41c9bb or later.
Azərbaycanca: CVE-2026-55995, open-iscsi proqramında aşkarlanan Double Free zəifliyidir. Bu boşluq autentifikasiya olunmamış MITM hücumçusuna xidmət rəddi (DoS) vəziyyəti yaratmağa imkan verir. Təsirə məruz qalan versiyalardan ən son 56718d4e9d1a4f51c30697b5c0534144bb41c9bb commit-inə qədər yeniləmə aparılmalıdır.
Related CVEs
link basis: same weakness class CWE-416
FAQ2
What software is affected by CVE-2026-55995, and is authentication required to exploit this vulnerability?
CVE-2026-55995 affects the open-iscsi software. Exploitation of this vulnerability does not require authentication, meaning it can be exploited by an unauthenticated attacker.
What is the primary threat posed by the CVE-2026-55995 Double Free vulnerability, and how can it be mitigated?
The primary threat is that a MITM (Man-in-the-Middle) attacker can cause a Denial of Service (DoS). To mitigate the vulnerability, affected versions must be updated to at least commit 56718d4e9d1a4f51c30697b5c0534144bb41c9bb.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.