First published: Thu Jan 03 2019(Updated: )
IBM Spectrum Scale (GPFS) 4.1.1, 4.2.0, 4.2.1, 4.2.2, 4.2.3, and 5.0.0 where the use of Local Read Only Cache (LROC) is enabled may caused read operation on a file to return data from a different file. IBM X-Force ID: 154440.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Spectrum Scale | >=4.1.1.0<=4.1.1.21 | |
IBM Spectrum Scale | >=4.2.0.0<=4.2.3.11 | |
IBM Spectrum Scale | >=5.0.0.0<=5.0.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-1993 is considered to be high due to its potential impact on data integrity.
To fix CVE-2018-1993, it is recommended to disable the Local Read Only Cache (LROC) feature or update to a patched version of IBM Spectrum Scale.
CVE-2018-1993 affects IBM Spectrum Scale versions 4.1.1 to 4.1.1.21, 4.2.0 to 4.2.3.11, and 5.0.0 to 5.0.2.0.
CVE-2018-1993 may cause read operations to return data from a different file, leading to potential data corruption or misuse.
A temporary workaround for CVE-2018-1993 is to disable the use of Local Read Only Cache (LROC) until an update can be implemented.