CVE-2018-14659: Medium severity red hat gluster storage vulnerability
The Gluster file system through versions 4.1.4 and 3.1.2 is vulnerable to a denial of service attack via use of the 'GFXATTRIOSTATSDUMPKEY' xattr. A remote, authenticated attacker could exploit this by mounting a Gluster volume and repeatedly calling 'setxattr(2)' to trigger a state dump and create an arbitrary number of files in the server's runtime directory.
Other sources
The Gluster file system through versions 4.1.4 and 3.1.2 is vulnerable to a denial of service attack via use of the "GFXATTRIOSTATSDUMPKEY" xattr. A remote, authenticated attacker could exploit this by mounting a Gluster volume and repeatedly calling "setxattr(2)" to trigger a state dump and create an arbitrary number of files in the server's runtime directory.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Gluster file system vulnerability?
The vulnerability ID for this Gluster file system vulnerability is CVE-2018-14659.
What is the severity level of CVE-2018-14659?
The severity level of CVE-2018-14659 is medium (6.5).
Which versions of the Gluster file system are affected by CVE-2018-14659?
The Gluster file system versions 4.1.4 and 3.1.2 are affected by CVE-2018-14659.
How can a remote, authenticated attacker exploit CVE-2018-14659?
A remote, authenticated attacker can exploit CVE-2018-14659 by mounting a Gluster volume and repeatedly calling 'setxattr(2)' to trigger a state dump and create a denial of service attack.
Are there any references for more information about CVE-2018-14659?
Yes, you can find more information about CVE-2018-14659 at the following references: [Bugzilla Red Hat](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1644583), [RHSA-2018:3431](https://access.redhat.com/errata/RHSA-2018:3431), [RHSA-2018:3432](https://access.redhat.com/errata/RHSA-2018:3432).