The iSNS daemon and utility programs
Go to file
RHEL Packaging Agent d92871624d Fix CVE-2026-55995: double-free in isns-utils attrs.c error paths
Backport upstream fix for CVE-2026-55995 to prevent
double-free vulnerabilities in isns-utils. The patch adds
NULL pointer assignments after isns_free() calls in two
error paths in attrs.c (string and opaque attribute
decoding), preventing potential denial-of-service attacks
when buf_get() fails.

CVE: CVE-2026-55995
Upstream patches:
 - 56718d4e9d.patch
Resolves: RHEL-219459

This commit was backported by Ymir, a Red Hat Enterprise Linux software maintenance AI agent.

Assisted-by: Ymir
2026-08-11 16:44:15 -07:00
.fmf run all upstream tests, update metadata to tmt/fmf 2026-08-11 16:43:46 -07:00
plans run all upstream tests, update metadata to tmt/fmf 2026-08-11 16:43:46 -07:00
tests run all upstream tests, update metadata to tmt/fmf 2026-08-11 16:43:46 -07:00
.gitignore Update to 0.103 2024-12-13 22:15:45 -08:00
isns-utils-0.103-CVE-2026-55995.patch Fix CVE-2026-55995: double-free in isns-utils attrs.c error paths 2026-08-11 16:44:15 -07:00
isns-utils.spec Fix CVE-2026-55995: double-free in isns-utils attrs.c error paths 2026-08-11 16:44:15 -07:00
isnsd.init Rebase to 0.93 2012-09-10 13:52:52 -07:00
isnsd.service Migrate to systemd. 2012-02-15 14:30:06 -06:00
sources Update to 0.103 2024-12-13 22:15:45 -08:00
test_as_installed.patch run all upstream tests, update metadata to tmt/fmf 2026-08-11 16:43:46 -07:00