Unrated severityNVD Advisory· Published Oct 31, 2018· Updated Aug 5, 2024
CVE-2018-14659
CVE-2018-14659
Description
The Gluster file system through versions 4.1.4 and 3.1.2 is vulnerable to a denial of service attack via use of the 'GF_XATTR_IOSTATS_DUMP_KEY' xattr. A remote, authenticated attacker could exploit this by mounting a Gluster volume and repeatedly calling 'setxattr(2)' to trigger a state dump and create an arbitrary number of files in the server's runtime directory.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- The Gluster Project/glusterfsv5Range: through 3.1.2 and 4.1.4
Patches
Vulnerability mechanics
References
7- access.redhat.com/errata/RHSA-2018:3431mitrevendor-advisoryx_refsource_REDHAT
- access.redhat.com/errata/RHSA-2018:3432mitrevendor-advisoryx_refsource_REDHAT
- access.redhat.com/errata/RHSA-2018:3470mitrevendor-advisoryx_refsource_REDHAT
- security.gentoo.org/glsa/201904-06mitrevendor-advisoryx_refsource_GENTOO
- bugzilla.redhat.com/show_bug.cgimitrex_refsource_CONFIRM
- lists.debian.org/debian-lts-announce/2018/11/msg00003.htmlmitremailing-listx_refsource_MLIST
- lists.debian.org/debian-lts-announce/2021/11/msg00000.htmlmitremailing-listx_refsource_MLIST
News mentions
0No linked articles in our index yet.