REDHAT-BUG-1635929: Medium severity gluster Gluster file system vulnerability
The Gluster file system through versions 4.1.4 and 3.1.2 is vulnerable to a denial of service attack via use of the "GFXATTRIOSTATSDUMPKEY" xattr. A remote, authenticated attacker could exploit this by mounting a Gluster volume and repeatedly calling "setxattr(2)" to trigger a state dump and create an arbitrary number of files in the server's runtime directory.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1635929?
The severity of REDHAT-BUG-1635929 is classified as a denial of service vulnerability, allowing potential disruption to the Gluster file system.
How do I fix REDHAT-BUG-1635929?
To fix REDHAT-BUG-1635929, you should upgrade your Gluster file system to a version later than 4.1.4 or 3.1.2.
What systems are affected by REDHAT-BUG-1635929?
The systems affected by REDHAT-BUG-1635929 include Gluster file system versions between 3.1.2 and 4.1.4.
Can REDHAT-BUG-1635929 be exploited remotely?
Yes, REDHAT-BUG-1635929 can be exploited remotely by an authenticated attacker who mounts a vulnerable Gluster volume.
What kind of attack does REDHAT-BUG-1635929 enable?
REDHAT-BUG-1635929 enables a denial of service attack via excessive state dump triggering through the "GF_XATTR_IOSTATS_DUMP_KEY" xattr.