Vulnerability Description
A flaw was found in the way dic_unserialize function of glusterfs does not handle negative key length values. An attacker could use this flaw to read memory from other locations into the stored dict value.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gluster | Glusterfs | >= 3.12.0, < 3.12.14 |
| Redhat | Virtualization Host | 4.0 |
| Redhat | Enterprise Linux Desktop | 6.0 |
| Redhat | Enterprise Linux Server | 6.0 |
| Redhat | Enterprise Linux Workstation | 6.0 |
| Debian | Debian Linux | 8.0 |
| Opensuse | Leap | 15.1 |
Related Weaknesses (CWE)
References
- http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00035.htmlMailing ListThird Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2607Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2608Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2892Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:3242Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:3470Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10911Issue TrackingThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/09/msg00021.htmlMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/11/msg00000.htmlMailing ListThird Party Advisory
- https://review.gluster.org/#/c/glusterfs/+/21067/PatchVendor Advisory
- https://security.gentoo.org/glsa/201904-06Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00035.htmlMailing ListThird Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2607Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2608Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2892Third Party Advisory
FAQ
What is CVE-2018-10911?
CVE-2018-10911 is a vulnerability with a CVSS score of 7.5 (HIGH). A flaw was found in the way dic_unserialize function of glusterfs does not handle negative key length values. An attacker could use this flaw to read memory from other locations into the stored dict v...
How severe is CVE-2018-10911?
CVE-2018-10911 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-10911?
Check the references section above for vendor advisories and patch information. Affected products include: Gluster Glusterfs, Redhat Virtualization Host, Redhat Enterprise Linux Desktop, Redhat Enterprise Linux Server, Redhat Enterprise Linux Workstation.