Wind River Support Network

HomeDefectsLIN1018-2984
Fixed

LIN1018-2984 : Security Advisory - glusterfs - CVE-2018-14659

Created: Nov 18, 2018    Updated: May 13, 2022
Resolved Date: Jan 28, 2019
Found In Version: unknown
Fix Version: 10.18.44.4
Severity: Standard
Applicable for: Wind River Linux LTS 18
Component/s: Userspace

Description

The Gluster file system through versions 4.1.4 and 3.1.2 is vulnerable to a denial of service attack via use of the 'GF_XATTR_IOSTATS_DUMP_KEY' xattr. A remote, authenticated attacker could exploit this by mounting a Gluster volume and repeatedly calling 'setxattr(2)' to trigger a state dump and create an arbitrary number of files in the server's runtime directory.

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-14659

CVEs


Live chat
Online