HomeClusterLabs Projects

High: libservices: fix use-after-free wrt. alert handling

Description

High: libservices: fix use-after-free wrt. alert handling

This could possibly lead to unsolicited information disclosure by the
means of standard output of the immediately preceding agent/resource
execution leaking into the log stream under some circumstances.
It was hence assigned CVE-2019-3885.

The provoked pathological state of pacemaker-execd daemon progresses
towards crashing it for hitting segmentation fault.

Details

Provenance
Jan Pokorný <jpokorny@redhat.com>Authored on Apr 2 2019, 4:13 AM
Parents
rP20988d643e76: Merge pull request #1747 from kgaillot/fixes
Branches
Unknown
Tags
Unknown

Event Timeline