First published: Wed Apr 18 2018(Updated: )
GlusterFS is a key building block of Red Hat Gluster Storage. It is based on a stackable user-space design and can deliver exceptional performance for diverse workloads. GlusterFS aggregates various storage servers over network interconnections into one large, parallel network file system.<br>Security Fix(es):<br><li> glusterfs: Privilege escalation via gluster_shared_storage when snapshot scheduling is enabled (CVE-2018-1088)</li> For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.<br>This issue was discovered by John Strunk (Red Hat).
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/glusterfs | <3.8.4-54.6.el7 | 3.8.4-54.6.el7 |
redhat/glusterfs | <3.8.4-54.6.el7 | 3.8.4-54.6.el7 |
redhat/glusterfs-api | <3.8.4-54.6.el7 | 3.8.4-54.6.el7 |
redhat/glusterfs-api-devel | <3.8.4-54.6.el7 | 3.8.4-54.6.el7 |
redhat/glusterfs-cli | <3.8.4-54.6.el7 | 3.8.4-54.6.el7 |
redhat/glusterfs-client-xlators | <3.8.4-54.6.el7 | 3.8.4-54.6.el7 |
redhat/glusterfs-debuginfo | <3.8.4-54.6.el7 | 3.8.4-54.6.el7 |
redhat/glusterfs-devel | <3.8.4-54.6.el7 | 3.8.4-54.6.el7 |
redhat/glusterfs-fuse | <3.8.4-54.6.el7 | 3.8.4-54.6.el7 |
redhat/glusterfs-libs | <3.8.4-54.6.el7 | 3.8.4-54.6.el7 |
redhat/glusterfs-rdma | <3.8.4-54.6.el7 | 3.8.4-54.6.el7 |
redhat/python-gluster | <3.8.4-54.6.el7 | 3.8.4-54.6.el7 |
redhat/glusterfs-api | <3.8.4-54.6.el7 | 3.8.4-54.6.el7 |
redhat/glusterfs-api-devel | <3.8.4-54.6.el7 | 3.8.4-54.6.el7 |
redhat/glusterfs-cli | <3.8.4-54.6.el7 | 3.8.4-54.6.el7 |
redhat/glusterfs-client-xlators | <3.8.4-54.6.el7 | 3.8.4-54.6.el7 |
redhat/glusterfs-debuginfo | <3.8.4-54.6.el7 | 3.8.4-54.6.el7 |
redhat/glusterfs-devel | <3.8.4-54.6.el7 | 3.8.4-54.6.el7 |
redhat/glusterfs-events | <3.8.4-54.6.el7 | 3.8.4-54.6.el7 |
redhat/glusterfs-fuse | <3.8.4-54.6.el7 | 3.8.4-54.6.el7 |
redhat/glusterfs-ganesha | <3.8.4-54.6.el7 | 3.8.4-54.6.el7 |
redhat/glusterfs-geo-replication | <3.8.4-54.6.el7 | 3.8.4-54.6.el7 |
redhat/glusterfs-libs | <3.8.4-54.6.el7 | 3.8.4-54.6.el7 |
redhat/glusterfs-rdma | <3.8.4-54.6.el7 | 3.8.4-54.6.el7 |
redhat/glusterfs-resource-agents | <3.8.4-54.6.el7 | 3.8.4-54.6.el7 |
redhat/glusterfs-server | <3.8.4-54.6.el7 | 3.8.4-54.6.el7 |
redhat/python-gluster | <3.8.4-54.6.el7 | 3.8.4-54.6.el7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2018:1136 is classified as important.
To fix RHSA-2018:1136, update to the latest version of the affected GlusterFS packages, specifically 3.8.4-54.6.el7.
Affected packages by RHSA-2018:1136 include glusterfs, glusterfs-api, glusterfs-cli, and others listed in the advisory.
Yes, RHSA-2018:1136 addresses an important security vulnerability in GlusterFS.
The recommended version for resolving RHSA-2018:1136 is 3.8.4-54.6.el7 for various GlusterFS packages.