Your submission was sent successfully! Close

You have successfully unsubscribed! Close

CVE-2010-2526

Published: 5 August 2010

The cluster logical volume manager daemon (clvmd) in lvm2-cluster in LVM2 before 2.02.72, as used in Red Hat Global File System (GFS) and other products, does not verify client credentials upon a socket connection, which allows local users to cause a denial of service (daemon exit or logical-volume change) or possibly have unspecified other impact via crafted control commands.

Priority

Medium

Status

Package Release Status
lvm2
Launchpad, Ubuntu, Debian
upstream
Released (2.02.72)
dapper
Released (2.02.02-1ubuntu1.6)
hardy
Released (2.02.26-1ubuntu9.1)
jaunty
Released (2.02.39-0ubuntu9.1)
karmic
Released (2.02.39-0ubuntu11.1)
lucid
Released (2.02.54-1ubuntu4.1)
Patches:
vendor: http://patch-tracker.debian.org/patch/series/view/lvm2/2.02.66-3/upstream-2.02.72.patch
vendor: http://patch-tracker.debian.org/patch/series/view/lvm2/2.02.39-8/CVE-2010-2526.patch