CVE-2018-10914: Null Pointer Dereference
A flaw was found in GlusterFS. A NULL pointer dereference vulnerability due to an improper implementation of the posixgetfilecontents function. An attacker could exploit this to perform a Denial of Service attack.
Other sources
It was found that an attacker could issue a xattr request via glusterfs FUSE to cause gluster brick process to crash which will result in a remote denial of service. If gluster multiplexing is enabled this will result in a crash of multiple bricks and gluster volumes.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this security issue?
The vulnerability ID is CVE-2018-10914.
What is the severity level of CVE-2018-10914?
The severity level of CVE-2018-10914 is medium.
How can an attacker exploit CVE-2018-10914?
An attacker can exploit CVE-2018-10914 by issuing a malicious xattr request via glusterfs FUSE, causing the gluster brick process to crash and resulting in a remote denial of service.
Which software versions are affected by CVE-2018-10914?
The affected versions include glusterfs 3.12.0 to 3.12.14, glusterfs 4.1.0 to 4.1.4, Gluster GlusterFS 3.12.0 to 3.12.14, Gluster GlusterFS 4.1.0 to 4.1.8, Redhat Virtualization Host 4.0, Redhat Enterprise Linux Server 6.0 and 7.0, Debian Debian Linux 8.0 and 9.0, and openSUSE Leap 15.1.
How can I fix CVE-2018-10914?
To fix CVE-2018-10914, update your glusterfs software to version 3.12.15 or 4.1.5, or apply the recommended patches provided by the vendor.