First published: Tue May 10 2022(Updated: )
Red Hat Gluster Storage is a software only scale-out storage solution that provides flexible and affordable unstructured data storage. It unifies data storage and infrastructure, increases performance, and improves availability and manageability to meet enterprise-level storage challenges.<br>Security Fix(es):<br><li> samba: Symlink race error can allow metadata read and modify outside of the exported share (CVE-2021-20316)</li> <li> samba: Information leak via symlinks of existance of files or directories outside of the exported share (CVE-2021-44141)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.<br>Users of samba with Red Hat Gluster Storage are advised to upgrade to these updated packages.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/libtalloc | <2.3.3-2.el8 | 2.3.3-2.el8 |
redhat/libtdb | <1.4.4-2.el8 | 1.4.4-2.el8 |
redhat/libtevent | <0.11.0-1.el8 | 0.11.0-1.el8 |
redhat/samba | <4.15.5-100.el8 | 4.15.5-100.el8 |
redhat/ctdb | <4.15.5-100.el8 | 4.15.5-100.el8 |
redhat/ctdb-debuginfo | <4.15.5-100.el8 | 4.15.5-100.el8 |
redhat/libsmbclient | <4.15.5-100.el8 | 4.15.5-100.el8 |
redhat/libsmbclient-debuginfo | <4.15.5-100.el8 | 4.15.5-100.el8 |
redhat/libsmbclient-devel | <4.15.5-100.el8 | 4.15.5-100.el8 |
redhat/libtalloc-debuginfo | <2.3.3-2.el8 | 2.3.3-2.el8 |
redhat/libtalloc-debugsource | <2.3.3-2.el8 | 2.3.3-2.el8 |
redhat/libtalloc-devel | <2.3.3-2.el8 | 2.3.3-2.el8 |
redhat/libtdb-debuginfo | <1.4.4-2.el8 | 1.4.4-2.el8 |
redhat/libtdb-debugsource | <1.4.4-2.el8 | 1.4.4-2.el8 |
redhat/libtdb-devel | <1.4.4-2.el8 | 1.4.4-2.el8 |
redhat/libtevent-debuginfo | <0.11.0-1.el8 | 0.11.0-1.el8 |
redhat/libtevent-debugsource | <0.11.0-1.el8 | 0.11.0-1.el8 |
redhat/libtevent-devel | <0.11.0-1.el8 | 0.11.0-1.el8 |
redhat/libwbclient | <4.15.5-100.el8 | 4.15.5-100.el8 |
redhat/libwbclient-debuginfo | <4.15.5-100.el8 | 4.15.5-100.el8 |
redhat/libwbclient-devel | <4.15.5-100.el8 | 4.15.5-100.el8 |
redhat/python3-samba | <4.15.5-100.el8 | 4.15.5-100.el8 |
redhat/python3-samba-debuginfo | <4.15.5-100.el8 | 4.15.5-100.el8 |
redhat/python3-talloc | <2.3.3-2.el8 | 2.3.3-2.el8 |
redhat/python3-talloc-debuginfo | <2.3.3-2.el8 | 2.3.3-2.el8 |
redhat/python3-talloc-devel | <2.3.3-2.el8 | 2.3.3-2.el8 |
redhat/python3-tdb | <1.4.4-2.el8 | 1.4.4-2.el8 |
redhat/python3-tdb-debuginfo | <1.4.4-2.el8 | 1.4.4-2.el8 |
redhat/python3-tevent | <0.11.0-1.el8 | 0.11.0-1.el8 |
redhat/python3-tevent-debuginfo | <0.11.0-1.el8 | 0.11.0-1.el8 |
redhat/samba-client | <4.15.5-100.el8 | 4.15.5-100.el8 |
redhat/samba-client-debuginfo | <4.15.5-100.el8 | 4.15.5-100.el8 |
redhat/samba-client-libs | <4.15.5-100.el8 | 4.15.5-100.el8 |
redhat/samba-client-libs-debuginfo | <4.15.5-100.el8 | 4.15.5-100.el8 |
redhat/samba-common | <4.15.5-100.el8 | 4.15.5-100.el8 |
redhat/samba-common-libs | <4.15.5-100.el8 | 4.15.5-100.el8 |
redhat/samba-common-libs-debuginfo | <4.15.5-100.el8 | 4.15.5-100.el8 |
redhat/samba-common-tools | <4.15.5-100.el8 | 4.15.5-100.el8 |
redhat/samba-common-tools-debuginfo | <4.15.5-100.el8 | 4.15.5-100.el8 |
redhat/samba-debuginfo | <4.15.5-100.el8 | 4.15.5-100.el8 |
redhat/samba-debugsource | <4.15.5-100.el8 | 4.15.5-100.el8 |
redhat/samba-devel | <4.15.5-100.el8 | 4.15.5-100.el8 |
redhat/samba-krb5-printing | <4.15.5-100.el8 | 4.15.5-100.el8 |
redhat/samba-krb5-printing-debuginfo | <4.15.5-100.el8 | 4.15.5-100.el8 |
redhat/samba-libs | <4.15.5-100.el8 | 4.15.5-100.el8 |
redhat/samba-libs-debuginfo | <4.15.5-100.el8 | 4.15.5-100.el8 |
redhat/samba-pidl | <4.15.5-100.el8 | 4.15.5-100.el8 |
redhat/samba-test-debuginfo | <4.15.5-100.el8 | 4.15.5-100.el8 |
redhat/samba-test-libs-debuginfo | <4.15.5-100.el8 | 4.15.5-100.el8 |
redhat/samba-vfs-glusterfs | <4.15.5-100.el8 | 4.15.5-100.el8 |
redhat/samba-vfs-glusterfs-debuginfo | <4.15.5-100.el8 | 4.15.5-100.el8 |
redhat/samba-vfs-iouring-debuginfo | <4.15.5-100.el8 | 4.15.5-100.el8 |
redhat/samba-winbind | <4.15.5-100.el8 | 4.15.5-100.el8 |
redhat/samba-winbind-clients | <4.15.5-100.el8 | 4.15.5-100.el8 |
redhat/samba-winbind-clients-debuginfo | <4.15.5-100.el8 | 4.15.5-100.el8 |
redhat/samba-winbind-debuginfo | <4.15.5-100.el8 | 4.15.5-100.el8 |
redhat/samba-winbind-krb5-locator | <4.15.5-100.el8 | 4.15.5-100.el8 |
redhat/samba-winbind-krb5-locator-debuginfo | <4.15.5-100.el8 | 4.15.5-100.el8 |
redhat/samba-winbind-modules | <4.15.5-100.el8 | 4.15.5-100.el8 |
redhat/samba-winbind-modules-debuginfo | <4.15.5-100.el8 | 4.15.5-100.el8 |
redhat/samba-winexe-debuginfo | <4.15.5-100.el8 | 4.15.5-100.el8 |
redhat/tdb-tools | <1.4.4-2.el8 | 1.4.4-2.el8 |
redhat/tdb-tools-debuginfo | <1.4.4-2.el8 | 1.4.4-2.el8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is RHSA-2022:1756.
The vulnerability affects packages such as libtalloc, libtdb, libtevent, samba, and ctdb among others.
You can remediate RHSA-2022:1756 by upgrading to the specified versions of the affected packages as listed in the advisory.
Failing to address RHSA-2022:1756 may leave your system vulnerable to security exploits that could compromise data integrity and availability.
Yes, detailed descriptions of the security issues are provided in the advisory associated with RHSA-2022:1756.