Bug 1590067 (CVE-2018-11218)
| Summary: | CVE-2018-11218 redis: Heap corruption in lua_cmsgpack.c | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | Sam Fowler <sfowler> |
| Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
| Status: | CLOSED ERRATA | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | CC: | apevec, chrisw, cmacedo, dffrench, drusso, fabian.deutsch, hhorak, jal233, jjoyce, jmadigan, jorton, jschluet, jshepherd, kbasil, lgriffin, lhh, lpeer, mariel, markmc, mburns, nathans, ngough, pwright, rcollet, rhos-maint, sclewis, security-response-team, slinaber, tdecacqu, trepel |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | redis 3.2.12, redis 4.0.10, redis 5.0-rc2 | Doc Type: | If docs needed, set a value |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2019-06-10 10:28:42 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 1591535, 1591536, 1591537, 1597564, 1599575, 1599576, 1599577, 1599578, 1599579, 1599580, 1599581, 1599582, 1599583 | ||
| Bug Blocks: | 1590065 | ||
|
Description
Sam Fowler
2018-06-12 01:35:10 UTC
External References: http://antirez.com/news/119 Created redis tracking bugs for this issue: Affects: epel-all [bug 1591537] Affects: fedora-all [bug 1591536] Patches: https://github.com/antirez/redis/commit/52a00201fca331217c3b4b8b634f6a0f57d6b7d3 https://github.com/antirez/redis/commit/5ccb6f7a791bf3490357b00a898885759d98bab0 This issue has been addressed in the following products: Red Hat OpenStack Platform 10.0 (Newton) Via RHSA-2019:0052 https://access.redhat.com/errata/RHSA-2019:0052 This issue has been addressed in the following products: Red Hat OpenStack Platform 13.0 (Queens) Via RHSA-2019:0094 https://access.redhat.com/errata/RHSA-2019:0094 This issue has been addressed in the following products: Red Hat Software Collections for Red Hat Enterprise Linux 7 Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUS Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS Red Hat Software Collections for Red Hat Enterprise Linux 6 Via RHSA-2019:1860 https://access.redhat.com/errata/RHSA-2019:1860 |