Red Hat Security Advisory 2017-3277-01

Red Hat Security Advisory 2017-3277-01 – The tcmu-runner packages provide a service that handles the complexity of the LIO kernel target’s userspace passthrough interface. It presents a C plugin API for extension modules that handle SCSI requests in ways not possible or suitable to be handled by LIO’s in-kernel backstores. Security Fix: A flaw was found in the implementation of CheckConfig method in handler_glfs.so of the tcmu-runner daemon. A local, non-root user with access to the D-Bus system bus could send a specially crafted string to CheckConfig method resulting in various kinds of segmentation fault.

Link: https://packetstormsecurity.com/files/145142/RHSA-2017-3277-01.txt