REDHAT-BUG-1487251: Null Pointer Dereference
A local non-root user with access to the D-Bus system bus can call the UnregisterHandler method implemented in the tcmu-runner daemon with the name of a handler loaded internally in tcmu-runner via dlopen() and cause a NULL pointer dereference resulting in DoS.
Upstream patch:
https://github.com/open-iscsi/tcmu-runner/commit/bb80e9c7a798f035768260ebdadffb6eb0786178
References:
http://seclists.org/oss-sec/2017/q3/207
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1487251?
The severity of REDHAT-BUG-1487251 is classified as medium with a score of 4.
How do I fix REDHAT-BUG-1487251?
To fix REDHAT-BUG-1487251, ensure you apply the upstream patch provided by the developers of tcmu-runner.
Who is affected by REDHAT-BUG-1487251?
REDHAT-BUG-1487251 affects local non-root users with access to the D-Bus system bus.
What exploit does REDHAT-BUG-1487251 enable?
REDHAT-BUG-1487251 enables a local user to cause a denial of service through a NULL pointer dereference.
Which software is impacted by REDHAT-BUG-1487251?
The impacted software by REDHAT-BUG-1487251 is open-iscsi tcmu-runner.