Red Hat released Important-severity updates for CVE-2026-55995, a double-free vulnerability in the iSNS attribute decoder used by open-isns/open-iscsi. An unauthenticated man-in-the-middle attacker could exploit the flaw to crash affected services and cause a denial of service; upstream versions through commit 56718d4e9d1a4f51c30697b5c0534144bb41c9bb are affected.
The fixes are available in isns-utils-0.101-4.el9_6.1 for RHEL 9.6 service variants and isns-utils-0.103-1.el10_0.1 for RHEL 10.0, covering x86_64, ARM64/aarch64, IBM Z/s390x, and Power ppc64le platforms. Organizations running affected RHEL systems, including SAP, telecommunications, extended-support, and lifecycle-support deployments, should apply the relevant Red Hat updates.

See real exploitation activity before you spend the cycle.
10 events from the most recent confirmed update back to the earliest known activity.
Alibaba Cloud Linux 3 published ALINUX3-SA-2026:0260, updating affected isns-utils, isns-utils-devel, and isns-utils-libs packages to remediate CVE-2026-55995. The vulnerability is network-accessible without privileges or user interaction and can cause high availability impact.
Red Hat issued Important-severity advisory RHSA-2026:61249 for RHEL 8, updating affected isns-utils, isns-utils-libs, and isns-utils-devel packages to remediate CVE-2026-55995. The remotely reachable unauthenticated double-free flaw in the open-isns/open-iscsi iSNS attribute decoder can cause denial of service.
Unity Linux published advisory UTSA-2026-104845, directing users to update the affected isns-utils package to remediate CVE-2026-55995. The advisory describes the flaw as an unauthenticated man-in-the-middle double-free vulnerability in open-iscsi that can cause denial of service.
Red Hat issued Important-severity advisory RHSA-2026:60385 to remediate CVE-2026-55995 in isns-utils, isns-utils-libs, and isns-utils-devel on affected RHEL 8 and RHEL AUS 8.6 systems. The vulnerability is an unauthenticated network-reachable double-free denial-of-service flaw in the open-isns/open-iscsi iSNS attribute decoder.
Red Hat issued Important-severity advisory RHSA-2026:59999 to update isns-utils on affected RHEL 9 systems and remediate CVE-2026-55995, a remotely exploitable unauthenticated double-free denial-of-service flaw in the open-iSNS attribute decoder.
Red Hat issued Important-severity advisory RHSA-2026:60005, releasing isns-utils 0.103-1.el10_0.1 to remediate CVE-2026-55995 for RHEL 10.0 support offerings.
Red Hat issued Important-severity advisory RHSA-2026:59996 to remediate CVE-2026-55995 in affected isns-utils packages on RHEL E4S 9.4. The flaw is a network-reachable double-free denial-of-service vulnerability in the open-isns/open-iscsi iSNS attribute decoder.
Red Hat issued Important-severity advisory RHSA-2026:60006, releasing isns-utils 0.101-4.el9_6.1 and associated libraries to remediate CVE-2026-55995 for RHEL 9.6 service variants.
TencentOS Server 3 published a patch for its affected isns-utils package to remediate CVE-2026-55995, a remotely exploitable unauthenticated vulnerability with high availability impact.
Red Hat documented CVE-2026-55995, a double-free in the open-isns/open-iscsi iSNS attribute decoder that an unauthenticated man-in-the-middle attacker can exploit to cause denial of service. The upstream fix was identified as commit 56718d4e9d1a4f51c30697b5c0534144bb41c9bb.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
11 references tracked. Mallory keeps watching after this page renders.
tenable.com
Open sourcetenable.com
Open sourcetenable.com
Open sourcetenable.com
Open sourcetenable.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcecwe.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.