CVE-2017-15096: Null Pointer Dereference
A flaw was found in GlusterFS in versions prior to 3.10. A null pointer dereference in sendbrickreq function in glusterfsd/src/gfattach.c may be used to cause denial of service.
Other sources
A flaw was found in glusterfs. A null pointer dereference in in sendbrickreq function in glusterfsd/src/gfattach.c may cause local denial of service.
References:
https://bugzilla.redhat.com/showbug.cgi?id=1502928
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-15096?
CVE-2017-15096 has a severity rating that indicates it could lead to a denial of service in affected versions of GlusterFS.
How do I fix CVE-2017-15096?
To remediate CVE-2017-15096, upgrade GlusterFS to version 3.10 or later.
Which versions of GlusterFS are affected by CVE-2017-15096?
CVE-2017-15096 affects GlusterFS versions prior to 3.10.
What is the potential impact of CVE-2017-15096?
The potential impact of CVE-2017-15096 is a denial of service condition due to a null pointer dereference.
Is there a workaround for CVE-2017-15096?
There is no documented workaround for CVE-2017-15096, so upgrading is the best solution.