Description
A flaw was found in glusterfs server through versions 4.1.4 and 3.1.2 which allowed repeated usage of GF_META_LOCK_KEY xattr. A remote, authenticated attacker could use this flaw to create multiple locks for single inode by using setxattr repetitively resulting in memory exhaustion of glusterfs server node.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2806-1 | glusterfs security update |
EUVD |
EUVD-2018-6555 | A flaw was found in glusterfs server through versions 4.1.4 and 3.1.2 which allowed repeated usage of GF_META_LOCK_KEY xattr. A remote, authenticated attacker could use this flaw to create multiple locks for single inode by using setxattr repetitively resulting in memory exhaustion of glusterfs server node. |
Ubuntu USN |
USN-4770-1 | GlusterFS vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-05T09:38:12.616Z
Reserved: 2018-07-27T00:00:00.000Z
Link: CVE-2018-14660
No data.
Status : Modified
Published: 2018-11-01T14:29:00.313
Modified: 2024-11-21T03:49:32.010
Link: CVE-2018-14660
OpenCVE Enrichment
No data.
Debian DLA
EUVD
Ubuntu USN