glusterfs-3.12.2-18.AXS4

エラータID: AXSA:2018-3346:04

Release date: 
Tuesday, October 9, 2018 - 16:55
Subject: 
glusterfs-3.12.2-18.AXS4
Affected Channels: 
Asianux Server 4 for x86_64
Severity: 
Moderate
Description: 

GlusterFS is a key building block of Asianux Gluster Storage. It is based on a stackable user-space design and can deliver exceptional performance for diverse workloads. GlusterFS aggregates various storage servers over network interconnections into one large, parallel network file system.

The glusterfs packages have been upgraded to upstream version 3.12.2, which provides a number of bug fixes over the previous version. (BZ#1594203)

Security Fix(es):

* glusterfs: Improper deserialization in dict.c:dict_unserialize() can allow attackers to read arbitrary memory (CVE-2018-10911)

For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.

Asianux would like to thank Michael Hanselmann (hansmi.ch) for reporting this issue.

CVE-2018-10911
A flaw was found in the way dic_unserialize function of glusterfs does not handle negative key length values. An attacker could use this flaw to read memory from other locations into the stored dict value.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. glusterfs-3.12.2-18.AXS4.src.rpm
    MD5: 0685678c7eec370e4157397b4bccb786
    SHA-256: c4c6a49736f2df59b789b6ac9911aa9015305e2b91aa621e16a8c2353987d960
    Size: 9.60 MB

Asianux Server 4 for x86_64
  1. glusterfs-3.12.2-18.AXS4.x86_64.rpm
    MD5: ead823f46b10a9907919a45d6ae498ce
    SHA-256: 6712977db1abf41379287f453b711e6f23da0813e7405a635d2f11b64213ea88
    Size: 509.90 kB
  2. glusterfs-api-3.12.2-18.AXS4.x86_64.rpm
    MD5: 80fe68f84c250d3828f8ebb2e10e8886
    SHA-256: d1dc89cea8607e1c36f5b7621aa274b062ad75530938b2edc10b5db5cf4fed37
    Size: 65.04 kB
  3. glusterfs-api-devel-3.12.2-18.AXS4.x86_64.rpm
    MD5: ef1773e62db2531b2fcd66162d3adcfb
    SHA-256: 045f406a2016ec7078cf71e678f6770a1e3f31e52e14a93312c68bc6873f6bf5
    Size: 17.77 kB
  4. glusterfs-client-xlators-3.12.2-18.AXS4.x86_64.rpm
    MD5: 3539414ae67a44cd5494d0e21e00b8ef
    SHA-256: 829af56b7ed20be157b168fe7b530091aec54ff9821926d71865d933152f9428
    Size: 1.34 MB
  5. glusterfs-devel-3.12.2-18.AXS4.x86_64.rpm
    MD5: cf30654e5ebfa51515b5bd8f1993343a
    SHA-256: f43cd26e23641de77b3ede3a4fab4b03189c2d0d6b78c6d77ae2b4582bcdbf6c
    Size: 158.40 kB
  6. glusterfs-fuse-3.12.2-18.AXS4.x86_64.rpm
    MD5: 1281f9b7765de83fbc775fde1c126ce9
    SHA-256: 76d98b29fc62996b8f4416848d4e19faa75bb70db8f2d45a4b8e370c8f045fd9
    Size: 110.96 kB
  7. glusterfs-libs-3.12.2-18.AXS4.x86_64.rpm
    MD5: 84449dc4c736ed24ecd066d413b372cb
    SHA-256: 611366edefcde3150dc92c9e756e7b344f7876a1f03066d0c57e6bd6583d0b31
    Size: 363.98 kB
  8. glusterfs-rdma-3.12.2-18.AXS4.x86_64.rpm
    MD5: fb4b5577fd0cd3a96ba37490aea22734
    SHA-256: 3f01fbb53577581b721e5290a079675193dafbe2845a9d1628aa74701d11d95f
    Size: 37.12 kB