Wind River Support Network


LIN10-4698 : Security Advisory - glusterfs - CVE-2018-10904

Created: Sep 17, 2018    Updated: Dec 24, 2018
Resolved Date: Oct 15, 2018
Found In Version:
Fix Version:
Severity: Standard
Applicable for: Wind River Linux LTS 17
Component/s: Userspace


It was found that glusterfs server does not properly sanitize file paths in the extended attribute which is used by the debug/io-stats translator. Attacker can use this flaw to create files and execute arbitrary code. To exploit this attacker would require sufficient access to modify the extended attributes of files on a gluster volume.

Other Downloads


Live chat