vulnerability

Oracle Linux: CVE-2018-10911: ELSA-2018-2892: glusterfs security, bug fix, and enhancement update (MODERATE) (Multiple Advisories)

Severity
5
CVSS
(AV:N/AC:L/Au:N/C:P/I:N/A:N)
Published
Sep 4, 2018
Added
Oct 10, 2018
Modified
Dec 3, 2025

Description

A flaw was found in the way dic_unserialize function of glusterfs does not handle negative key length values. An attacker could use this flaw to read memory from other locations into the stored dict value.
A flaw was found in dict.c:dict_unserialize function of glusterfs, dic_unserialize function does not handle negative key length values. An attacker could use this flaw to read memory from other locations into the stored dict value.

Solutions

oracle-linux-upgrade-glusterfsoracle-linux-upgrade-glusterfs-apioracle-linux-upgrade-glusterfs-api-develoracle-linux-upgrade-glusterfs-clioracle-linux-upgrade-glusterfs-client-xlatorsoracle-linux-upgrade-glusterfs-develoracle-linux-upgrade-glusterfs-fuseoracle-linux-upgrade-glusterfs-libsoracle-linux-upgrade-glusterfs-rdmaoracle-linux-upgrade-python2-gluster
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.