Bug 1568973

Summary: CVE-2018-1088 glusterfs: Privilege escalation via gluster_shared_storage when snapshot scheduling is enabled [fedora-all]
Product: [Community] GlusterFS Reporter: Kaleb KEITHLEY <kkeithle>
Component: snapshotAssignee: Amar Tumballi <atumball>
Status: CLOSED CURRENTRELEASE QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: mainlineCC: anoopcs, atumball, bugs, extras-qa, humble.devassy, jonathansteffan, kkeithle, matthias, ndevos, ramkrsna, rhinduja, rhs-bugs, sankarshan, sisharma, storage-qa-internal, vbellur
Target Milestone: ---Keywords: Security, SecurityTracking, Triaged
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: Release Note
Doc Text:
Story Points: ---
Clone Of: 1568969
: 1570428 1570430 1570432 (view as bug list) Environment:
Last Closed: 2018-08-13 04:43:49 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1568832, 1568844    
Bug Blocks: 1558721, 1570428, 1570430, 1570432    

Comment 1 Kaleb KEITHLEY 2018-04-18 13:17:31 UTC
filed against mainline, applies to 4.0, 3.12, and 3.10. Please do backports

Comment 2 Amar Tumballi 2018-08-13 04:43:49 UTC
The patches are already in all the different branches, and also fixed in master.