Description
The Gluster file system through versions 4.1.4 and 3.1.2 is vulnerable to a denial of service attack via use of the 'GF_XATTR_IOSTATS_DUMP_KEY' xattr. A remote, authenticated attacker could exploit this by mounting a Gluster volume and repeatedly calling 'setxattr(2)' to trigger a state dump and create an arbitrary number of files in the server's runtime directory.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1565-1 | glusterfs security update |
Debian DLA |
DLA-2806-1 | glusterfs security update |
EUVD |
EUVD-2018-6554 | The Gluster file system through versions 4.1.4 and 3.1.2 is vulnerable to a denial of service attack via use of the 'GF_XATTR_IOSTATS_DUMP_KEY' xattr. A remote, authenticated attacker could exploit this by mounting a Gluster volume and repeatedly calling 'setxattr(2)' to trigger a state dump and create an arbitrary number of files in the server's runtime directory. |
Ubuntu USN |
USN-4770-1 | GlusterFS vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-05T09:38:13.101Z
Reserved: 2018-07-27T00:00:00.000Z
Link: CVE-2018-14659
No data.
Status : Modified
Published: 2018-10-31T19:29:00.627
Modified: 2024-11-21T03:49:31.857
Link: CVE-2018-14659
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
EUVD
Ubuntu USN