vulnerability
Oracle Linux: CVE-2018-10911: ELSA-2018-2892: glusterfs security, bug fix, and enhancement update (MODERATE) (Multiple Advisories)
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 5 | (AV:N/AC:L/Au:N/C:P/I:N/A:N) | Sep 4, 2018 | Oct 10, 2018 | Dec 3, 2025 |
Severity
5
CVSS
(AV:N/AC:L/Au:N/C:P/I:N/A:N)
Published
Sep 4, 2018
Added
Oct 10, 2018
Modified
Dec 3, 2025
Description
A flaw was found in the way dic_unserialize function of glusterfs does not handle negative key length values. An attacker could use this flaw to read memory from other locations into the stored dict value.
A flaw was found in dict.c:dict_unserialize function of glusterfs, dic_unserialize function does not handle negative key length values. An attacker could use this flaw to read memory from other locations into the stored dict value.
A flaw was found in dict.c:dict_unserialize function of glusterfs, dic_unserialize function does not handle negative key length values. An attacker could use this flaw to read memory from other locations into the stored dict value.
Solutions
oracle-linux-upgrade-glusterfsoracle-linux-upgrade-glusterfs-apioracle-linux-upgrade-glusterfs-api-develoracle-linux-upgrade-glusterfs-clioracle-linux-upgrade-glusterfs-client-xlatorsoracle-linux-upgrade-glusterfs-develoracle-linux-upgrade-glusterfs-fuseoracle-linux-upgrade-glusterfs-libsoracle-linux-upgrade-glusterfs-rdmaoracle-linux-upgrade-python2-gluster
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.