REDHAT-BUG-1635926: Medium severity gluster Gluster file system vulnerability
The Gluster file system through versions 4.1.4 and 3.1.2 is vulnerable to a denial of service attack via use of the "GFMETALOCKKEY" xattr. A remote, authenticated attacker could exploit this by mounting a Gluster volume and repeatedly calling "setxattr(2)" to trigger an out-of-memory error and resultant denial of service.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1635926?
The severity of REDHAT-BUG-1635926 is classified as a denial of service vulnerability.
How do I fix REDHAT-BUG-1635926?
To fix REDHAT-BUG-1635926, update the Gluster file system to a version later than 4.1.4 or 3.1.2.
Who is affected by REDHAT-BUG-1635926?
The vulnerability REDHAT-BUG-1635926 affects users of Gluster file system versions between 4.1.4 and 3.1.2.
What can an attacker do with REDHAT-BUG-1635926?
An attacker can exploit REDHAT-BUG-1635926 to cause an out-of-memory error, leading to denial of service.
Is authentication required to exploit REDHAT-BUG-1635926?
Yes, exploitation of REDHAT-BUG-1635926 requires remote, authenticated access to the Gluster volume.