First published: Tue Feb 21 2023(Updated: )
In Gluster GlusterFS 11.0, there is an xlators/cluster/dht/src/dht-common.c dht_setxattr_mds_cbk use-after-free.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Gluster GlusterFS | =11.0 | |
ubuntu/glusterfs | <10.1-1ubuntu0.2 | 10.1-1ubuntu0.2 |
ubuntu/glusterfs | <10.3-4ubuntu0.2 | 10.3-4ubuntu0.2 |
ubuntu/glusterfs | <10.3-5ubuntu0.1 | 10.3-5ubuntu0.1 |
ubuntu/glusterfs | <11.1-1 | 11.1-1 |
debian/glusterfs | <=5.5-3<=9.2-1<=10.3-5 | 11.1-4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Gluster GlusterFS vulnerability is CVE-2022-48340.
The severity of CVE-2022-48340 is high with a severity value of 7.5.
The vulnerability in Gluster GlusterFS 11.0 manifests as a use-after-free issue in the dht_setxattr_mds_cbk function in dht-common.c.
Gluster GlusterFS 11.0 is affected by CVE-2022-48340.
Yes, a fix is available for CVE-2022-48340. It is recommended to update to a patched version of Gluster GlusterFS.