Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

Fedora 21: xfsprogs Security Update - CVE-2012-2150 Information Disclosure

fedora
Calendar Grey August 19, 2015
Dist Fedora Esm H88
xfs_metadump vulnerability in xfsprogs may reveal confidential disk information. Upgrade immediately to protect your Fedora 21 system from potential threats.
Gabriel Vlasiu reported that xfs_metadump, part of the xfsprogs suite of tools for the XFS filesystem, did not properly obfuscate data

Summary

A set of commands to use the XFS filesystem, including mkfs.xfs.

XFS is a high performance journaling filesystem which originated

on the SGI IRIX platform. It is completely multi-threaded, can

support large files and large filesystems, extended attributes,

variable block sizes, is extent based, and makes extensive use of

Btrees (directories, extents, free space) to aid both performance

and scalability.

Refer to the documentation at for complete details. This implementation is on-disk compatible

with the IRIX version of XFS.

Update Information:

Gabriel Vlasiu reported that xfs_metadump, part of the xfsprogs suite of tools for the XFS filesystem, did not properly obfuscate data. xfs_metadump properly obfuscates active metadata, but the rest of the space within that fs block comes through in the clear. This could lead to exposure of stale disk data via the produced metadump image.

The expectation of xfs_metadump is to obfuscate all but the shortest names in the metadata, as noted in the manpage:

By default, xfs_metadump obfuscates most file (regular file, directory and symbolic link) names and extended attribute names to allow the dumps to be sent without revealing confidential information. Extended attribute values are zeroed and no data is copied. The only exceptions are file or attribute names that are 4 or less characters in length. Also file names that span extents (this can only occur with...

Read the Full Advisory

Change Log

* Thu Jul 30 2015 Eric Sandeen 3.2.2-2 - Fix CVE-2012-2150 * Thu Dec 4 2014 Eric Sandeen 3.2.2-1 - New upstream release

References


[ 1 ] Bug #817696 - CVE-2012-2150 xfsprogs: xfs_metadump information disclosure flaw https://bugzilla.redhat.com/show_bug.cgi?id=817696

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update xfsprogs' at the command line. For more information, refer to "Managing Software with yum", available at .

Severity
important
Lowest
Low
Medium
High
Critical

Name: xfsprogs
Product: Fedora 21
Version: 3.2.2
Release: 2.fc21
URL: Summary : Utilities for managing the XFS filesystem

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here