Home / Security / Advisories / NTAP-20190401-0001
NTAP-20190401-0001 — May 2018 GNU C Library Vulnerabilities in NetApp Products
Published 2019-04-01 · Updated 2022-07-01 · Status: Final · Exploitation: Public · Severity: CRITICAL 9.8 · ONTAP affected: Yes
Product family: ONTAP · SolidFire / NetApp HCI · Other NetApp products | ONTAP-relevant | highest CVSS: 9.8
CVEs in this advisory
- CVE-2017-18269 — CRITICAL · CVSS 9.8 · site index
- CVE-2018-11236 — CRITICAL · CVSS 9.8 · site index
- CVE-2018-11237 — HIGH · CVSS 7.8 · site index
What the CVE records say
CVE-2017-18269 — An SSE2-optimized memmove implementation for i386 in sysdeps/i386/i686/multiarch/memcpy-sse2-unaligned.S in the GNU C Library (aka glibc or libc6) 2.21 through 2.27 does not correctly perform the overlapping memory check if the source memory range spans the middle of the address space, resulting in corrupt data being produced by the copy operation. This may disclose information to context-dependent attackers, or result in a denial of service, or, possibly, code execution.
CVE-2018-11236 — stdlib/canonicalize.c in the GNU C Library (aka glibc or libc6) 2.27 and earlier, when processing very long pathname arguments to the realpath function, could encounter an integer overflow on 32-bit architectures, leading to a stack-based buffer overflow and, potentially, arbitrary code execution.
CVE-2018-11237 — An AVX-512-optimized implementation of the mempcpy function in the GNU C Library (aka glibc or libc6) 2.27 and earlier may write data beyond the target buffer, leading to a buffer overflow in __mempcpy_avx512_no_vzeroupper.
Impact
Successful exploitation of these vulnerabilities could lead to disclosure of sensitive information, addition or modification of data or Denial of Service (DoS).
Affected products
- Data ONTAP Edge
- NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H300E/H500E/H700E/H410S
- NetApp HCI Baseboard Management Controller (BMC) - H410C
- NetApp SolidFire & HCI Management Node
- SnapProtect
Official fixes
- NetApp SolidFire & HCI Management Node — vendor fix ↗
- NetApp SolidFire & HCI Management Node — vendor fix ↗
- NetApp HCI Baseboard Management Controller (BMC) - H410C — vendor fix ↗
What to do
- Check the affected products listed above against the official advisory's affected-versions table — that is where the exact ONTAP 9 release, ONTAP tool, or management product versions are named.
- If affected and a fixed release exists, plan the upgrade — see the ONTAP upgrade runbook.
- If exploitation is listed as "active", treat remediation as urgent and review exposure (management LIFs, ONTAP S3, SnapMirror endpoints).
- Harden in parallel: security hardening baseline and ransomware protection on ONTAP.
Related reading
- Common ONTAP problems (FAQ) — plain-language symptoms and fixes
- ONTAP security hardening — baseline lockdown guidance
- Ransomware protection on ONTAP — SnapLock, SnapMirror vaulting, Anomaly Detection
- ONTAP error messages index — EMS/WAFL/NFS/SnapMirror messages
- Every NetApp advisory published in 2019