CVE-2017-15096
published 2017-10-26CVE-2017-15096: A flaw was found in GlusterFS in versions prior to 3.10. A null pointer dereference in send_brick_req function in glusterfsd/src/gf_attach.c may be used to…
PriorityP47low3.3CVSS 3.0
AVLACLPRLUINSUCNINAL
EPSS
0.32%
23.9th percentile
A flaw was found in GlusterFS in versions prior to 3.10. A null pointer dereference in send_brick_req function in glusterfsd/src/gf_attach.c may be used to cause denial of service.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | glusterfs | < glusterfs 3.12.2-2 (bookworm) | glusterfs 3.12.2-2 (bookworm) |
| gluster | glusterfs | <= 3.9.0 | — |
| gluster | glusterfs | >= 0 < 3.12.2-2 | 3.12.2-2 |
| gluster | glusterfs | >= 0 < 3.12.2-2 | 3.12.2-2 |
| gluster | glusterfs | >= 0 < 3.12.2-2 | 3.12.2-2 |
| gluster | glusterfs | >= 0 < 3.12.2-2 | 3.12.2-2 |
| red_hat_inc | glusterfs | — | — |
CVSS provenance
nvdv3.03.3LOWCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
osv3.3LOW
vendor_debian3.3LOW
vendor_redhat3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vxhq-jp57-mcrm: A flaw was found in GlusterFS in versions prior to 3
ghsa_unreviewed·2022-05-17
CVE-2017-15096 [LOW] CWE-476 GHSA-vxhq-jp57-mcrm: A flaw was found in GlusterFS in versions prior to 3
A flaw was found in GlusterFS in versions prior to 3.10. A null pointer dereference in send_brick_req function in glusterfsd/src/gf_attach.c may be used to cause denial of service.
OSV
CVE-2017-15096: A flaw was found in GlusterFS in versions prior to 3
osv·2017-10-26·CVSS 3.3
CVE-2017-15096 [LOW] CVE-2017-15096: A flaw was found in GlusterFS in versions prior to 3
A flaw was found in GlusterFS in versions prior to 3.10. A null pointer dereference in send_brick_req function in glusterfsd/src/gf_attach.c may be used to cause denial of service.
Red Hat
glusterfs: Null pointer dereference in send_brick_req function in glusterfsd/src/gf_attach.c
vendor_redhat·2017-10-17·CVSS 3.3
CVE-2017-15096 [LOW] CWE-119 glusterfs: Null pointer dereference in send_brick_req function in glusterfsd/src/gf_attach.c
glusterfs: Null pointer dereference in send_brick_req function in glusterfsd/src/gf_attach.c
A flaw was found in GlusterFS in versions prior to 3.10. A null pointer dereference in send_brick_req function in glusterfsd/src/gf_attach.c may be used to cause denial of service.
Package: glusterfs (Red Hat Enterprise Linux 6) - Not affected
Package: glusterfs (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2017-15096: glusterfs - A flaw was found in GlusterFS in versions prior to 3.10. A null pointer derefere...
vendor_debian·2017·CVSS 3.3
CVE-2017-15096 [LOW] CVE-2017-15096: glusterfs - A flaw was found in GlusterFS in versions prior to 3.10. A null pointer derefere...
A flaw was found in GlusterFS in versions prior to 3.10. A null pointer dereference in send_brick_req function in glusterfsd/src/gf_attach.c may be used to cause denial of service.
Scope: local
bookworm: resolved (fixed in 3.12.2-2)
bullseye: resolved (fixed in 3.12.2-2)
forky: resolved (fixed in 3.12.2-2)
sid: resolved (fixed in 3.12.2-2)
trixie: resolved (fixed in 3.12.2-2)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-15096 glusterfs: Null pointer dereference in send_brick_req function in glusterfsd/src/gf_attach.c [fedora-all]
bugzilla·2017-10-23·CVSS 3.3
CVE-2017-15096 [LOW] CVE-2017-15096 glusterfs: Null pointer dereference in send_brick_req function in glusterfsd/src/gf_attach.c [fedora-all]
CVE-2017-15096 glusterfs: Null pointer dereference in send_brick_req function in glusterfsd/src/gf_attach.c [fedora-all]
+++ This bug was initially created as a clone of Bug #1504256 +++
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being
Bugzilla
CVE-2017-15096 glusterfs: Null pointer dereference in send_brick_req function in glusterfsd/src/gf_attach.c [fedora-all]
bugzilla·2017-10-19·CVSS 3.3
CVE-2017-15096 [LOW] CVE-2017-15096 glusterfs: Null pointer dereference in send_brick_req function in glusterfsd/src/gf_attach.c [fedora-all]
CVE-2017-15096 glusterfs: Null pointer dereference in send_brick_req function in glusterfsd/src/gf_attach.c [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: thi
Bugzilla
CVE-2017-15096 glusterfs: Null pointer dereference in send_brick_req function in glusterfsd/src/gf_attach.c
bugzilla·2017-10-19·CVSS 3.3
CVE-2017-15096 [LOW] CVE-2017-15096 glusterfs: Null pointer dereference in send_brick_req function in glusterfsd/src/gf_attach.c
CVE-2017-15096 glusterfs: Null pointer dereference in send_brick_req function in glusterfsd/src/gf_attach.c
A flaw was found in glusterfs. A null pointer dereference in in send_brick_req function in glusterfsd/src/gf_attach.c may cause local denial of service.
References:
https://bugzilla.redhat.com/show_bug.cgi?id=1502928
Discussion:
Created glusterfs tracking bugs for this issue:
Affects: fedora-all [bug 1504256]
---
Analysis
Only local DoS of glusterfsd is possible with this. Impact of this flaw is low.
---
It's not even a DoS of glusterfsd. Worst case is that gf_attach runs out of memory, which would be a failure anyway, and then fails with a SIGSEGV in STACK_DESTROY (the other two functions check for NULL) instead of ENOMEM. Not sure GlusterD (management daemon) would even
2017-10-26
Published