CVE-2018-10911Integer Overflow or Wraparound in Glusterfs

Severity
7.5HIGHNVD
EPSS
4.3%
top 11.06%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 4
Latest updateApr 30

Description

A flaw was found in the way dic_unserialize function of glusterfs does not handle negative key length values. An attacker could use this flaw to read memory from other locations into the stored dict value.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages8 packages

NVDgluster/glusterfs3.12.03.12.14+1
Debiangluster/glusterfs< 4.1.4-1+3
CVEListV5red_hat/glusterfsn/a
NVDopensuse/leap15.1

Also affects: Debian Linux 8.0, 9.0

Patches

🔴Vulnerability Details

3
GHSA
GHSA-x86v-j2gh-g3w6: A flaw was found in the way dic_unserialize function of glusterfs does not handle negative key length values2022-04-30
OSV
CVE-2018-10911: A flaw was found in the way dic_unserialize function of glusterfs does not handle negative key length values2018-09-04
CVEList
CVE-2018-10911: A flaw was found in the way dic_unserialize function of glusterfs does not handle negative key length values2018-09-04

📋Vendor Advisories

3
Ubuntu
GlusterFS vulnerabilities2021-03-15
Red Hat
glusterfs: Improper deserialization in dict.c:dict_unserialize() can allow attackers to read arbitrary memory2018-09-04
Debian
CVE-2018-10911: glusterfs - A flaw was found in the way dic_unserialize function of glusterfs does not handl...2018

💬Community

4
Bugzilla
CVE-2018-10911 glusterfs: Improper deserialization in dict.c:dict_unserialize() can allow attackers to read arbitrary memory2018-09-05
Bugzilla
CVE-2018-10911 glusterfs: Improper deserialization in dict.c:dict_unserialize() can allow attackers to read arbitrary memory [fedora-all]2018-09-04
Bugzilla
CVE-2018-10911 glusterfs: Improper deserialization in dict.c:dict_unserialize() can allow attackers to read arbitrary memory2018-09-04
Bugzilla
CVE-2018-10911 glusterfs: Improper deserialization in dict.c:dict_unserialize() can allow attackers to read arbitrary memory2018-07-17
CVE-2018-10911 — Integer Overflow or Wraparound | cvebase