Oval Definition:oval:com.redhat.rhsa:def:20182892
Revision Date:2018-10-09Version:637
Title:RHSA-2018:2892: glusterfs security, bug fix, and enhancement update (Moderate)
Description:GlusterFS is a key building block of Red Hat Gluster Storage. It is based on a stackable user-space design and can deliver exceptional performance for diverse workloads. GlusterFS aggregates various storage servers over network interconnections into one large, parallel network file system.

  • The glusterfs packages have been upgraded to upstream version 3.12.2, which provides a number of bug fixes over the previous version. (BZ#1594203)

    Security Fix(es):

  • glusterfs: Improper deserialization in dict.c:dict_unserialize() can allow attackers to read arbitrary memory (CVE-2018-10911)

    For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.

    Red Hat would like to thank Michael Hanselmann (hansmi.ch) for reporting this issue.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2018-10911
    RHSA-2018:2892
    RHSA-2018:2892-00
    RHSA-2018:2892-01
    Platform(s):Red Hat Enterprise Linux 6
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 6 is installed
  • AND
  • glusterfs is earlier than 0:3.12.2-18.el6
  • AND glusterfs is signed with Red Hat redhatrelease2 key
  • glusterfs-api is earlier than 0:3.12.2-18.el6
  • AND glusterfs-api is signed with Red Hat redhatrelease2 key
  • glusterfs-api-devel is earlier than 0:3.12.2-18.el6
  • AND glusterfs-api-devel is signed with Red Hat redhatrelease2 key
  • glusterfs-cli is earlier than 0:3.12.2-18.el6
  • AND glusterfs-cli is signed with Red Hat redhatrelease2 key
  • glusterfs-client-xlators is earlier than 0:3.12.2-18.el6
  • AND glusterfs-client-xlators is signed with Red Hat redhatrelease2 key
  • glusterfs-devel is earlier than 0:3.12.2-18.el6
  • AND glusterfs-devel is signed with Red Hat redhatrelease2 key
  • glusterfs-fuse is earlier than 0:3.12.2-18.el6
  • AND glusterfs-fuse is signed with Red Hat redhatrelease2 key
  • glusterfs-libs is earlier than 0:3.12.2-18.el6
  • AND glusterfs-libs is signed with Red Hat redhatrelease2 key
  • glusterfs-rdma is earlier than 0:3.12.2-18.el6
  • AND glusterfs-rdma is signed with Red Hat redhatrelease2 key
  • BACK