{"id":"CVE-2017-1000198","details":"tcmu-runner daemon version 0.9.0 to 1.2.0 is vulnerable to invalid memory references in the handler_glfs.so handler resulting in denial of service","modified":"2026-07-08T12:53:46.972383Z","published":"2017-11-17T02:29:00.927Z","related":["SUSE-SU-2017:2601-1"],"references":[{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2017:3277"},{"type":"FIX","url":"https://github.com/open-iscsi/tcmu-runner/commit/61bd03e600d2abf309173e9186f4d465bb1b7157"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/open-iscsi/tcmu-runner","events":[{"introduced":"0579395e3227bd4dee4bc8bf643a69b1694b26a0"},{"last_affected":"3d335660333b98cd5bdb8983a619c3b00b814b3e"},{"fixed":"61bd03e600d2abf309173e9186f4d465bb1b7157"}],"database_specific":{"cpe":["cpe:2.3:a:tcmu-runner_project:tcmu-runner:0.9.0:*:*:*:*:*:*:*","cpe:2.3:a:tcmu-runner_project:tcmu-runner:0.9.1:*:*:*:*:*:*:*","cpe:2.3:a:tcmu-runner_project:tcmu-runner:0.9.2:*:*:*:*:*:*:*","cpe:2.3:a:tcmu-runner_project:tcmu-runner:0.9.3:*:*:*:*:*:*:*","cpe:2.3:a:tcmu-runner_project:tcmu-runner:0.9.4:*:*:*:*:*:*:*","cpe:2.3:a:tcmu-runner_project:tcmu-runner:1.0.5:*:*:*:*:*:*:*","cpe:2.3:a:tcmu-runner_project:tcmu-runner:1.1.0:*:*:*:*:*:*:*","cpe:2.3:a:tcmu-runner_project:tcmu-runner:1.1.1:*:*:*:*:*:*:*","cpe:2.3:a:tcmu-runner_project:tcmu-runner:1.1.2:*:*:*:*:*:*:*","cpe:2.3:a:tcmu-runner_project:tcmu-runner:1.1.3:*:*:*:*:*:*:*","cpe:2.3:a:tcmu-runner_project:tcmu-runner:1.2.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"0.9.0"},{"last_affected":"0.9.0"},{"introduced":"0.9.1"},{"last_affected":"0.9.1"},{"introduced":"0.9.2"},{"last_affected":"0.9.2"},{"introduced":"0.9.3"},{"last_affected":"0.9.3"},{"introduced":"0.9.4"},{"last_affected":"0.9.4"},{"introduced":"1.0.5"},{"last_affected":"1.0.5"},{"introduced":"1.1.0"},{"last_affected":"1.1.0"},{"introduced":"1.1.1"},{"last_affected":"1.1.1"},{"introduced":"1.1.2"},{"last_affected":"1.1.2"},{"introduced":"1.1.3"},{"last_affected":"1.1.3"},{"introduced":"1.2.0"},{"last_affected":"1.2.0"}],"source":["CPE_STRING","REFERENCES"]}}],"versions":["0.9.0","0.9.1","0.9.2","0.9.3","0.9.4","1.0.5","1.1.0","1.1.1","1.1.2","1.1.3","1.2.0","v1.2.0","v1.1.3","v1.1.2","v1.1.1","v1.1.0","v1.0.4","v1.0.3","v1.0.2","v1.0.1","v1.0.0","v0.9.4","v0.9.3","v0.9.2","v0.9.1","v0.9.0"],"database_specific":{"vanir_signatures_modified":"2026-07-08T12:53:46Z","vanir_signatures":[{"target":{"file":"glfs.c","function":"glfs_check_config"},"deprecated":false,"digest":{"function_hash":"48320263962876170658503604704800417228","length":911},"id":"CVE-2017-1000198-89bbaa9e","signature_type":"Function","signature_version":"v1","source":"https://github.com/open-iscsi/tcmu-runner/commit/61bd03e600d2abf309173e9186f4d465bb1b7157"},{"source":"https://github.com/open-iscsi/tcmu-runner/commit/61bd03e600d2abf309173e9186f4d465bb1b7157","target":{"file":"glfs.c"},"deprecated":false,"digest":{"line_hashes":["83983374689110734186866958739253717943","29357817856763059695477614314031294880","90299902222730314812035884148277478109","50615059462416866350128779556774858780","159341827478939936822425548843054013485","147619493334019110576477789003094344698","20899424300631971301750274369162575062","61413331478810338677911664105148752161","47898239324497825234221507909183569067","318298441011063056419600511128703069913","307270516897114086389089309365557398274","102658351946251237516308395819258870982","247050131883643515677544879745944303150","54760159850670024712130383477837415822","271521318181615709852418590217931794269","258940195847271936054241840397790787688","27624777171849645834954900548420881227","305396861213881164280879965210591717450","268946220282145907340129162958319282499","176599756418310875256346020145675566087","203107571801642258761985700063764998778","199821021502124982708901380331929880383","59477459178106042367739672323938567545","94401702839603171307247602670158193484","183774410016888749332415943007808496369","113880570475306895469662337782913601981","242591157509798737631423722575097096761","134330720570107292743739570801365857744","194005263928973847800198906079303715730","27587655273087012576120605797400540614","199541399525865746707323517616719366996","45242360179913030430908206837064893573","242591157509798737631423722575097096761","42545984356137525688038506315565104755","161955534889956523465563832255288273072","165517228553161373442161938105280314997","15171180050828930552569129307008105452","50285755908865119224224254004311882577","100533217236712072332204653338616350158","253844001929172605253645439798360260911","159884210952761358736590994074952426282","193284272323856779355789607367735907903","116499317484955578288733279187839380013","116953730017078514660639661512295776096","212106037202478921199104178251064141182","75130280924677371593611408575558244898","105160326740310771326470489551165867337","15857189464765210559973668755690471170","121306417863163459796662199110889748814"],"threshold":0.9},"id":"CVE-2017-1000198-bb55b6e8","signature_type":"Line","signature_version":"v1"}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-1000198.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}