Denial of Service Vulnerability in GlusterFS by Red Hat
CVE-2017-15096

3.3LOW

Key Information:

Vendor
Red Hat
Status
Vendor
CVE Published:
26 October 2017

Summary

A vulnerability in GlusterFS allows a null pointer dereference in the send_brick_req function located in the glusterfsd/src/gf_attach.c file. This flaw can be exploited to trigger a denial of service, causing the application to become unresponsive. Users of GlusterFS versions prior to 3.10 should take immediate action to mitigate this issue.

Affected Version(s)

GlusterFS Prior to 3.10

References

CVSS V3.1

Score:
3.3
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.