CVE-2022-48340: Use After Free
Published Feb 21, 2023
·Updated
In Gluster GlusterFS 11.0, there is an xlators/cluster/dht/src/dht-common.c dhtsetxattrmdscbk use-after-free.
Affected Software
6 affected componentsFixes available
ubuntu/glusterfs<10.1-1ubuntu0.2
10.1-1ubuntu0.2
ubuntu/glusterfs<10.3-4ubuntu0.2
10.3-4ubuntu0.2
ubuntu/glusterfs<10.3-5ubuntu0.1
10.3-5ubuntu0.1
ubuntu/glusterfs<11.1-1
11.1-1
debian/glusterfs<=5.5-3, <=9.2-1, <=10.3-5
11.1-4
gluster GlusterFS=11.0
Remediation
Patch Available
Event History
Feb 21, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Jan 12, 2024
Data Sourced
via Launchpad·12:13 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this Gluster GlusterFS vulnerability?
The vulnerability ID for this Gluster GlusterFS vulnerability is CVE-2022-48340.
2
What is the severity of CVE-2022-48340?
The severity of CVE-2022-48340 is high with a severity value of 7.5.
3
How does the vulnerability in Gluster GlusterFS 11.0 manifest?
The vulnerability in Gluster GlusterFS 11.0 manifests as a use-after-free issue in the dht_setxattr_mds_cbk function in dht-common.c.
4
What software version is affected by CVE-2022-48340?
Gluster GlusterFS 11.0 is affected by CVE-2022-48340.
5
Is there a fix for CVE-2022-48340?
Yes, a fix is available for CVE-2022-48340. It is recommended to update to a patched version of Gluster GlusterFS.