Database/Control plane, storage & DevOps
GlusterFS (dict_unserialize): A negative key length in a serialized dict makes the server read memory from elsewhere in
CVSS 6.5CVE-2018-10911Control plane, storage & DevOpscurated
Impact
A negative key length in a serialized dict makes the server read memory from elsewhere in the process into a returned value. The client gets back chunks of brick process memory, which on a shared brick can contain other tenants' file data and credentials.
Who can reach it
Any authenticated gluster client able to send a crafted RPC to a brick.
What to do
Upgrade glusterfs to 4.1.4 / 3.12.x-fixed or later and restart the bricks. Rotate any secrets that lived in the brick process address space if you believe the flaw was exercised.
References
Related entries
- Ceph CephX authentication protocol: The CephX signature calculation can be bypassed, so an on-path attacker can alterCVE-2018-1129 · Ceph CephX authentication protocolMedium
- Intel Core and Xeon CPUs - INTEL-SA-00210: This one is availability, not confidentiality, and it is the mostCVE-2018-12207 · Intel Core and Xeon CPUs - INTEL-SA-00210Medium
- Nouveau display driver (in-tree Linux nouveau, NV117): Remote denial of service against a workstation or node runningCVE-2018-3979 · Nouveau display driver (in-tree Linux nouveau, NV117)Medium
- Intel CPUs supporting TSX, including Cascade Lake Xeon Scalable - INTEL-SA-00270: Same class of in-flight data leakCVE-2019-11135 · Intel CPUs supporting TSX, including Cascade Lake Xeon Scalable - INTEL-SA-00270Medium
- Ceph RGW: HTTP header injection via a newline in the CORS ExposeHeader tagCVE-2021-3524 · Ceph RGWMedium
- Ceph: Key length incorrectly passed to the encryption algorithmCVE-2021-3979 · CephMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.