• 公告ID (KylinSec-SA-2024-1552)

摘要:

glusterfs security update

安全等级: High

公告ID: KylinSec-SA-2024-1552

发布日期: 2024年3月15日

关联CVE: CVE-2022-48340  

  • 详细介绍

1. 漏洞描述

   

GlusterFS is a distributed file-system capable of scaling to several petabytes. It aggregates various storage bricks over TCP/IP interconnect into one large parallel network filesystem. GlusterFS is one of the most sophisticated file systems in terms of features and extensibility. It borrows a powerful concept called Translators from GNU Hurd kernel. Much of the code in GlusterFS is in user space and easily manageable.

Security Fix(es):

In Gluster GlusterFS 11.0, there is an xlators/cluster/dht/src/dht-common.c dht_setxattr_mds_cbk use-after-free.(CVE-2022-48340)

2. 影响范围

cve名称 产品 组件 是否受影响
CVE-2022-48340 KY3.5.2 glusterfs Fixed

3. 影响组件

    glusterfs

4. 修复版本

   

KY3.5.2

软件名称 架构 版本号
glusterfs-resource-agents noarch 10.0-9.ky3_5
libgfxdr0 x86_64 10.0-9.ky3_5
libgfchangelog0 x86_64 10.0-9.ky3_5
glusterfs-thin-arbiter x86_64 10.0-9.ky3_5
libglusterfs0 x86_64 10.0-9.ky3_5
libglusterd0 x86_64 10.0-9.ky3_5
glusterfs-extra-xlators x86_64 10.0-9.ky3_5
glusterfs-client-xlators x86_64 10.0-9.ky3_5
libglusterfs-devel x86_64 10.0-9.ky3_5
libgfxdr-devel x86_64 10.0-9.ky3_5
glusterfs-cli x86_64 10.0-9.ky3_5
glusterfs-events x86_64 10.0-9.ky3_5
glusterfs-fuse x86_64 10.0-9.ky3_5
glusterfs-server x86_64 10.0-9.ky3_5
libgfapi-devel x86_64 10.0-9.ky3_5
glusterfs-cloudsync-plugins x86_64 10.0-9.ky3_5
glusterfs-help x86_64 10.0-9.ky3_5
libgfrpc0 x86_64 10.0-9.ky3_5
glusterfs-geo-replication x86_64 10.0-9.ky3_5
python3-gluster x86_64 10.0-9.ky3_5
libgfchangelog-devel x86_64 10.0-9.ky3_5
glusterfs x86_64 10.0-9.ky3_5
libgfrpc-devel x86_64 10.0-9.ky3_5
libgfapi0 x86_64 10.0-9.ky3_5
libgfchangelog-devel aarch64 10.0-9.ky3_5
glusterfs-thin-arbiter aarch64 10.0-9.ky3_5
libglusterd0 aarch64 10.0-9.ky3_5
libgfchangelog0 aarch64 10.0-9.ky3_5
libgfxdr0 aarch64 10.0-9.ky3_5
glusterfs aarch64 10.0-9.ky3_5
python3-gluster aarch64 10.0-9.ky3_5
glusterfs-fuse aarch64 10.0-9.ky3_5
libglusterfs-devel aarch64 10.0-9.ky3_5
libgfrpc0 aarch64 10.0-9.ky3_5
glusterfs-geo-replication aarch64 10.0-9.ky3_5
glusterfs-help aarch64 10.0-9.ky3_5
glusterfs-events aarch64 10.0-9.ky3_5
glusterfs-cli aarch64 10.0-9.ky3_5
glusterfs-cloudsync-plugins aarch64 10.0-9.ky3_5
glusterfs-client-xlators aarch64 10.0-9.ky3_5
glusterfs-extra-xlators aarch64 10.0-9.ky3_5
libgfrpc-devel aarch64 10.0-9.ky3_5
glusterfs-server aarch64 10.0-9.ky3_5
libgfapi0 aarch64 10.0-9.ky3_5
libglusterfs0 aarch64 10.0-9.ky3_5
libgfxdr-devel aarch64 10.0-9.ky3_5
libgfapi-devel aarch64 10.0-9.ky3_5

5. 修复方法


方法一:下载安装包进行升级安装
1、通过下载链接下载需要升级的升级包保存,如 xxx.rpm
2、通过rpm命令升级,如 rpm -Uvh xxx.rpm

方法二:通过软件源进行升级安装
1、保持能够连接上互联网
2、通过yum命令升级指定的包,如 yum install 包名

6. 下载链接

   

KY3.5.2:

x86_64:

     glusterfs-resource-agents   

     libgfxdr0   

     libgfchangelog0   

     glusterfs-thin-arbiter   

     libglusterfs0   

     libglusterd0   

     glusterfs-extra-xlators   

     glusterfs-client-xlators   

     libglusterfs-devel   

     libgfxdr-devel   

     glusterfs-cli   

     glusterfs-events   

     glusterfs-fuse   

     glusterfs-server   

     libgfapi-devel   

     glusterfs-cloudsync-plugins   

     glusterfs-help   

     libgfrpc0   

     glusterfs-geo-replication   

     python3-gluster   

     libgfchangelog-devel   

     glusterfs   

     libgfrpc-devel   

     libgfapi0   

aarch64:

     glusterfs-resource-agents   

     libgfchangelog-devel   

     glusterfs-thin-arbiter   

     libglusterd0   

     libgfchangelog0   

     libgfxdr0   

     glusterfs   

     python3-gluster   

     glusterfs-fuse   

     libglusterfs-devel   

     libgfrpc0   

     glusterfs-geo-replication   

     glusterfs-help   

     glusterfs-events   

     glusterfs-cli   

     glusterfs-cloudsync-plugins   

     glusterfs-client-xlators   

     glusterfs-extra-xlators   

     libgfrpc-devel   

     glusterfs-server   

     libgfapi0   

     libglusterfs0   

     libgfxdr-devel   

     libgfapi-devel   

上一篇:KylinSec-SA-2024-1551 下一篇:KylinSec-SA-2024-3155