CVE-2018-16878: Medium severity ClusterLabs Pacemaker vulnerability
A flaw was found in pacemaker up to and including version 2.0.1. An insufficient verification inflicted preference of uncontrolled processes can lead to DoS
Other sources
A flaw was found in pacemaker. An insufficient verification inflicted preference of uncontrolled processes can lead to DoS
References: https://bugzilla.redhat.com/showbug.cgi?id=1649942
— Red Hat
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2018-16878?
CVE-2018-16878 is a vulnerability found in pacemaker up to and including version 2.0.1.
What is the severity of CVE-2018-16878?
The severity of CVE-2018-16878 is medium with a severity value of 5.5.
How does CVE-2018-16878 impact pacemaker?
CVE-2018-16878 can lead to a denial-of-service (DoS) attack due to insufficient verification inflicted preference of uncontrolled processes.
Which software versions are affected by CVE-2018-16878?
Pacemaker versions up to and including 2.0.1 are affected by CVE-2018-16878.
How can I fix CVE-2018-16878?
To fix CVE-2018-16878, update pacemaker to version 2.0.2 or higher.