Severity
3.3LOW
EPSS
0.1%
top 82.55%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 26
Latest updateMay 17

Description

A flaw was found in GlusterFS in versions prior to 3.10. A null pointer dereference in send_brick_req function in glusterfsd/src/gf_attach.c may be used to cause denial of service.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:LExploitability: 1.8 | Impact: 1.4

Affected Packages3 packages

Debianglusterfs< 3.12.2-2+3
CVEListV5red_hat,_inc./glusterfsPrior to 3.10

🔴Vulnerability Details

3
GHSA
GHSA-vxhq-jp57-mcrm: A flaw was found in GlusterFS in versions prior to 32022-05-17
CVEList
CVE-2017-15096: A flaw was found in GlusterFS in versions prior to 32017-10-26
OSV
CVE-2017-15096: A flaw was found in GlusterFS in versions prior to 32017-10-26

📋Vendor Advisories

2
Red Hat
glusterfs: Null pointer dereference in send_brick_req function in glusterfsd/src/gf_attach.c2017-10-17
Debian
CVE-2017-15096: glusterfs - A flaw was found in GlusterFS in versions prior to 3.10. A null pointer derefere...2017

💬Community

3
Bugzilla
CVE-2017-15096 glusterfs: Null pointer dereference in send_brick_req function in glusterfsd/src/gf_attach.c [fedora-all]2017-10-23
Bugzilla
CVE-2017-15096 glusterfs: Null pointer dereference in send_brick_req function in glusterfsd/src/gf_attach.c [fedora-all]2017-10-19
Bugzilla
CVE-2017-15096 glusterfs: Null pointer dereference in send_brick_req function in glusterfsd/src/gf_attach.c2017-10-19
CVE-2017-15096 (LOW CVSS 3.3) | A flaw was found in GlusterFS in ve | cvebase.io