REDHAT-BUG-1632974: Buffer Overflow
The Gluster file system through versions 3.12 and 4.1.4 is vulnerable to a buffer overflow in the "features/index" translator via the code handling the "GFXATTRCLRLKCMD" xattr in the "plgetxattr" function. A remote authenticated attacker could exploit this on a mounted volume to cause a denial of service.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1632974?
The severity of REDHAT-BUG-1632974 is considered critical due to the potential for remote exploitation leading to denial of service.
How do I fix REDHAT-BUG-1632974?
To fix REDHAT-BUG-1632974, upgrade the Gluster file system to version 4.1.5 or later.
What versions are affected by REDHAT-BUG-1632974?
The affected versions by REDHAT-BUG-1632974 include Gluster file system 3.12 and up to 4.1.4.
What kind of attack does REDHAT-BUG-1632974 allow?
REDHAT-BUG-1632974 allows a remote authenticated attacker to exploit a buffer overflow vulnerability, resulting in a denial of service.
In which function is the vulnerability of REDHAT-BUG-1632974 located?
The vulnerability in REDHAT-BUG-1632974 is located in the 'pl_getxattr' function handling the 'GF_XATTR_CLRLK_CMD' xattr.