Re: [Gluster-users] Question about CVE-2018-10924

2018-10-30 Thread Hongzhi, Song
The following link says: the issues just exist in v3.12 series and above. https://security-tracker.debian.org/tracker/CVE-2018-10924 I have look into the code on v3.11. There is no commit that introduced the issue. So I think v3.11 doesn't require the CVE patch. --Hongzhi On 10/30/2018

Re: [Gluster-users] Question about CVE-2018-10924

2018-10-30 Thread Hongzhi, Song
Hi Pranith, Do you know which versions have the problem about fsync? https://bugzilla.redhat.com/show_bug.cgi?id=1611785#c1 --Hongzhi On 10/30/2018 05:20 PM, Hongzhi, Song wrote: Hi Pranith and other friends, Does this CVE apply for glusger-v3.11.1? I applied the patch for v3.11.1. There

Re: [Gluster-users] Question about CVE-2018-10924

2018-10-30 Thread Pranith Kumar Karampuri
On Tue, Oct 30, 2018 at 2:51 PM Hongzhi, Song wrote: > Hi Pranith and other friends, > > Does this CVE apply for glusger-v3.11.1? > It was later found to be not a CVE, only a memory leak. No, this bug is introduced in 3.12 branch and fixed in 3.12 branch as well. Patch that introduced leak: