CVE-2018-1993: Infoleak
IBM Spectrum Scale (GPFS) 4.1.1, 4.2.0, 4.2.1, 4.2.2, 4.2.3, and 5.0.0 where the use of Local Read Only Cache (LROC) is enabled may caused read operation on a file to return data from a different file. IBM X-Force ID: 154440.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2018-1993?
The severity of CVE-2018-1993 is considered to be high due to its potential impact on data integrity.
How do I fix CVE-2018-1993?
To fix CVE-2018-1993, it is recommended to disable the Local Read Only Cache (LROC) feature or update to a patched version of IBM Spectrum Scale.
What versions of IBM Spectrum Scale are affected by CVE-2018-1993?
CVE-2018-1993 affects IBM Spectrum Scale versions 4.1.1 to 4.1.1.21, 4.2.0 to 4.2.3.11, and 5.0.0 to 5.0.2.0.
What kind of data integrity issues does CVE-2018-1993 cause?
CVE-2018-1993 may cause read operations to return data from a different file, leading to potential data corruption or misuse.
Is there a workaround for CVE-2018-1993 until a patch is applied?
A temporary workaround for CVE-2018-1993 is to disable the use of Local Read Only Cache (LROC) until an update can be implemented.