CVE-2019-10153: Medium severity clusterlabs vulnerability
A flaw was discovered in fence-agents, prior to version 4.3.4, where using non-ASCII characters in a guest VM's comment or other fields would cause fencerhevm to exit with an exception. In cluster environments, this could lead to preventing automated recovery or otherwise denying service to clusters of which that VM is a member.
Other sources
It was discovered that in fence-agents prior to 4.3.4, including non-ASCII characters in a guest VM's comment or other fields would cause fencerhevm to exit with an exception. In cluster environments, this could lead to preventing automated recovery or otherwise denying service to clusters of which that VM is a member.
Product bug:
https://bugzilla.redhat.com/showbug.cgi?id=1670460
Upstream fix:
https://github.com/ClusterLabs/fence-agents/pull/255 https://github.com/ClusterLabs/fence-agents/pull/272
— Red Hat
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2019-10153?
CVE-2019-10153 is a vulnerability discovered in fence-agents, prior to version 4.3.4, where using non-ASCII characters in a guest VM's comment or other fields would cause fence_rhevm to exit with an exception.
How does CVE-2019-10153 impact cluster environments?
In cluster environments, CVE-2019-10153 could lead to preventing automated recovery or otherwise denying service to clusters.
What is the severity of CVE-2019-10153?
CVE-2019-10153 has a severity level of medium (5).
How do I fix CVE-2019-10153?
To fix CVE-2019-10153, upgrade to version 4.3.4 of fence-agents or later.
Where can I find more information about CVE-2019-10153?
You can find more information about CVE-2019-10153 on the Red Hat Security Advisory RHSA-2019:2037, Bugzilla entry, and GitHub pull request.