CVE 2018-10861: mon: auth checks not correct for pool ops (issue#24838, Jason Dillaman)
The RBD C API’s rbd_discard method and the C++ API’s Image::discard method
now enforce a maximum length of 2GB. This restriction prevents overflow of
the result code.