First published: Wed Sep 19 2018(Updated: )
IBM GPFS (IBM Spectrum Scale 5.0.1.0 and 5.0.1.1) allows a local, unprivileged user to cause a kernel panic on a node running GPFS by accessing a file that is stored on a GPFS file system with mmap, or by executing a crafted file stored on a GPFS file system. IBM X-Force ID: 148805.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Spectrum Scale | =5.0.1.0 | |
IBM Spectrum Scale | =5.0.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1782 is considered to have a high severity due to its potential to cause kernel panic.
To mitigate CVE-2018-1782, it is recommended to update IBM Spectrum Scale to a version that is not affected, such as versions beyond 5.0.1.1.
Local, unprivileged users on nodes running IBM Spectrum Scale versions 5.0.1.0 and 5.0.1.1 are affected by CVE-2018-1782.
No, CVE-2018-1782 requires local access to the file system to exploit the vulnerability.
CVE-2018-1782 can lead to a kernel panic, resulting in system instability and potential downtime.