安全公告详情

NS-SA-2025-0216

2025-09-30 16:49:52

简介

moderate: blktrace/lvm2 security update

严重级别

moderate

主题

An update for blktrace/lvm2 is now available for NewStart CGSL MAIN 6.06.
NewStart Security has rated this update as having a security impact of moderate. A Common Vunlnerability Scoring System(CVSS)base score, which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.

详细描述

blktrace:
lvm2:


Security Fix(es):
blktrace: (aka Block IO Tracing) 1.2.0, as used with the Linux kernel and Android, has a buffer overflow in the dev_map_read function in btt/devmap.c because the device and devno arrays are too small, as demonstrated by an invalid free when using the btt program with a crafted file.(CVE-2018-10689)
blktrace: bugfix
lvm2: The cluster logical volume manager daemon (clvmd) in lvm2-cluster in LVM2 before 2.02.72, as used in Red Hat Global File System (GFS) and other products, does not verify client credentials upon a socket connection, which allows local users to cause a denial of service (daemon exit or logical-volume change) or possibly have unspecified other impact via crafted control commands.(CVE-2010-2526)
lvm2: bugfix


Solution:
For details on how to apply this update, which includes the changes described in this advisory, refer to:
http://security.gd-linux.com/how_to_apply_patch.html
Remember the build tag is 6.06.01B6.

影响组件

  • blktrace
  • lvm2

影响产品

  • CGSL MAIN 6.06

更新包

{"fix":[{"product":"CGSL MAIN 6.06","pkgs":[{"binary":["blktrace-1.2.0-10.zncgsl6.x86_64.rpm"],"source":"blktrace-1.2.0-10.zncgsl6.src.rpm"},{"binary":["device-mapper-1.02.181-3.0.1.zncgsl6_6.2.t2.0.x86_64.rpm","device-mapper-event-1.02.181-3.0.1.zncgsl6_6.2.t2.0.x86_64.rpm","device-mapper-event-libs-1.02.181-3.0.1.zncgsl6_6.2.t2.0.x86_64.rpm","device-mapper-libs-1.02.181-3.0.1.zncgsl6_6.2.t2.0.x86_64.rpm","lvm2-2.03.14-3.0.1.zncgsl6_6.2.t2.0.x86_64.rpm","lvm2-libs-2.03.14-3.0.1.zncgsl6_6.2.t2.0.x86_64.rpm"],"source":"lvm2-2.03.14-3.0.1.zncgsl6_6.2.t2.0.src.rpm"}]}]}

CVE

参考