PT-2018-2976 · Clusterlabs+5 · Pacemaker+5

Jan Pokorný

·

Published

2018-12-10

·

Updated

2023-09-29

·

CVE-2018-16878

CVSS v3.1

6.2

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Pacemaker versions up to and including 2.0.1
Description The issue is related to an uncontrolled resource consumption in the Pacemaker cluster resource management software, which can be exploited to cause a denial of service (DoS). This could allow an attacker to disrupt service operations. The estimated number of potentially affected devices worldwide is not specified. There is no information about real-world incidents where this issue was exploited.
Recommendations For Pacemaker versions up to and including 2.0.1, update to a version later than 2.0.1 to resolve the issue. As a temporary workaround, consider restricting access to the cluster resource management functionality to minimize the risk of exploitation.

Fix

DoS

Resource Exhaustion

Weakness Enumeration

Related Identifiers

ALT-PU-2019-2068
ALT-PU-2019-2069
BDU:2019-02965
CESA-2019_1279
CVE-2018-16878
DLA-2519-1
MGASA-2019-0394
OPENSUSE-SU-2019:1400-1
OPENSUSE-SU-2019_1342-1
OPENSUSE-SU-2019_1400-1
RHSA-2019:1278
RHSA-2019:1279
RHSA-2019_1278
RHSA-2019_1279
SUSE-SU-2019:1047-1
SUSE-SU-2019:1108-1
SUSE-SU-2019:1209-1
SUSE-SU-2019:2268-1
SUSE-SU-2020:1072-1
USN-3952-1

Affected Products

Alt Linux
Centos
Pacemaker
Red Hat
Suse
Ubuntu