The cluster logical volume manager daemon (clvmd) in lvm2-cluster in LVM2 before 2.02.72, as used in Red Hat Global File System (GFS) and other products, does not verify client credentials upon a socket connection, which allows local users to cause a denial of service (daemon exit or logical-volume change) or possibly have unspecified other impact via crafted control commands. We have an ebuild in portage, and I suggest we stabilize it. I'm not adding arches because the severity seems to be relatively low.
Arches, please stabilize =sys-fs/lvm2-2.02.73. target keywords: alpha amd64 arm hppa ia64 ppc ppc64 s390 sh sparc x86 The following are also needed at the same time for safe stabilization: =sys-fs/udev-151-r4 (bug 324507) =sys-fs/cryptsetup-1.1.2 (bug 327689)
x86 stable
amd64 done
(In reply to comment #1) > =sys-fs/udev-151-r4 (bug 324507) HPPA needs a glibc patch before >sys-fs/udev-146 works properly.
arm stable
alpha/ia64/s390/sh/sparc stable @amd64: the version requested is .73, not .72
(In reply to comment #6) > alpha/ia64/s390/sh/sparc stable > > @amd64: the version requested is .73, not .72 > Sorry my bad :-/ amd64 done again
Arches, please stable 2.02.73-r1 which fixes a linking bug that breaks snapshotting. See bug #335205 for further information.
+ 01 Sep 2010; <chainsaw@gentoo.org> lvm2-2.02.73-r1.ebuild: + Fast tracking to AMD64 stable, --as-needed breakage fixed by Diego E. + "Flameeyes" Pettenò; closes bug #335205. For security bug #327689.
CVE-2010-2526 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-2526): The cluster logical volume manager daemon (clvmd) in lvm2-cluster in LVM2 before 2.02.72, as used in Red Hat Global File System (GFS) and other products, does not verify client credentials upon a socket connection, which allows local users to cause a denial of service (daemon exit or logical-volume change) or possibly have unspecified other impact via crafted control commands.
alpha/arm/ia64/s390/sh/sparc stable
ppc64 done
(In reply to comment #13) > ppc64 done > ppc64 stabilized wrong version, should be 2.02.73-r1
Marked ppc/ppc64 (the right version) stable.
Stable for HPPA.
@ppc64, are you able to stabilize =sys-fs/2.02.73-r1 ? Thank you.
GLSA request filed.
security: what is the status of this?
@ppc, looks like we missed this somehow. Please stabilize =sys-fs/lvm2-2.02.73-r1. Thank you. (In reply to comment #20) > security: > what is the status of this? Robin, are you referring to the missed ppc stabilization, or something else?
ppc stable, last arch done
Thanks again, folks. Reverting to [glsa].
security: this has been pending a GLSA for many months now?
This issue was resolved and addressed in GLSA 201412-09 at http://security.gentoo.org/glsa/glsa-201412-09.xml by GLSA coordinator Sean Amoss (ackle).