CVE-2018-10927: Input Validation
A flaw was found in RPC request using gfs3lookupreq in glusterfs server. An authenticated attacker could use this flaw to leak information and execute remote denial of service by crashing gluster brick process.
Other sources
The Gluster file system has a vulnerability allowing for remote attackers to extract the status of arbitrary files and crash the brick process with a crafted filename.
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this flaw?
The vulnerability ID for this flaw is CVE-2018-10927.
What is the severity of CVE-2018-10927?
The severity of CVE-2018-10927 is high with a CVSS score of 8.1.
How does this vulnerability affect the glusterfs server?
This vulnerability affects the glusterfs server and can be exploited by an authenticated attacker to leak information and execute remote denial of service by crashing the gluster brick process.
Which software versions are affected by this vulnerability?
The software versions affected by this vulnerability are glusterfs versions up to exclusive 3.12.14 and 4.1.4, Redhat Enterprise Linux Server versions 6.0 and 7.0, Debian Debian Linux versions 8.0 and 9.0, Redhat Virtualization Host version 4.0, and openSUSE Leap version 15.1.
Are there any remedies available to fix this vulnerability?
Yes, there are remedies available to fix this vulnerability, which can be found in the references provided.