CVE-2018-10924
published 2018-09-04CVE-2018-10924: It was discovered that fsync(2) system call in glusterfs client code leaks memory. An authenticated attacker could use this flaw to launch a denial of service…
PriorityP431medium6.5CVSS 3.0
AVNACLPRLUINSUCNINAH
EPSS
1.88%
77.3th percentile
It was discovered that fsync(2) system call in glusterfs client code leaks memory. An authenticated attacker could use this flaw to launch a denial of service attack by making gluster clients consume memory of the host machine.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | glusterfs | < glusterfs 4.0.1-1 (bookworm) | glusterfs 4.0.1-1 (bookworm) |
| gluster | glusterfs | >= 0 < 4.0.1-1 | 4.0.1-1 |
| gluster | glusterfs | >= 0 < 4.0.1-1 | 4.0.1-1 |
| gluster | glusterfs | >= 0 < 4.0.1-1 | 4.0.1-1 |
| gluster | glusterfs | >= 0 < 4.0.1-1 | 4.0.1-1 |
| gluster | glusterfs | >= 0 < 3.4.2-1ubuntu1+esm1 | 3.4.2-1ubuntu1+esm1 |
| gluster | glusterfs | >= 0 < 3.7.6-1ubuntu1+esm1 | 3.7.6-1ubuntu1+esm1 |
| gluster | glusterfs | >= 0 < 3.13.2-1ubuntu1+esm1 | 3.13.2-1ubuntu1+esm1 |
| gluster | glusterfs | >= 3.12.11 < 3.12.14 | 3.12.14 |
| gluster | glusterfs | >= 4.0.0 < 4.1.4 | 4.1.4 |
| red_hat | glusterfs | — | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.06.8MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:C
osv6.5MEDIUM
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
GlusterFS vulnerabilities
vendor_ubuntu·2021-03-15·CVSS 5.0
CVE-2018-10929 [MEDIUM] GlusterFS vulnerabilities
Title: GlusterFS vulnerabilities
Summary: Several security issues were fixed in GlusterFS.
It was discovered that GlusterFS incorrectly handled network requests. An
attacker could possibly use this issue to cause a denial of service. This issue
only affected Ubuntu 14.04 ESM. (CVE-2014-3619)
It was discovered that GlusterFS incorrectly handled user permissions. An
authenticated attacker could possibly use this to add himself to a trusted
storage pool and perform privileged operations on volumes. This issue only
affected Ubuntu 16.04 ESM and Ubuntu 18.04 ESM. (CVE-2018-10841)
It was discovered that GlusterFS incorrectly handled mounting gluster
volumes. An attacker could possibly use this issue to also mount shared
gluster volumes and escalate privileges through malicious cronjobs. This
Red Hat
glusterfs: Denial-of-service via fsync(2) in Gluster FUSE client
vendor_redhat·2018-09-04·CVSS 5.3
CVE-2018-10924 [MEDIUM] CWE-400 glusterfs: Denial-of-service via fsync(2) in Gluster FUSE client
glusterfs: Denial-of-service via fsync(2) in Gluster FUSE client
It was discovered that fsync(2) system call in glusterfs client code leaks memory. An authenticated attacker could use this flaw to launch a denial of service attack by making gluster clients consume memory of the host machine.
It was discovered that fsync(2) system call in glusterfs client code leaks memory. An authenticated attacker could use this flaw to launch a denial of service attack by making gluster clients consume memory of the host machine.
Statement: This issue did not affect the versions of glusterfs as shipped with Red Hat Enterprise Linux 6 and 7, and Red Hat Gluster Storage 3.
Package: glusterfs (Red Hat Enterprise Linux 6) - Not affected
Package: glusterfs (Red Hat Enterprise Linux 7) - Not affected
Pac
Debian
CVE-2018-10924: glusterfs - It was discovered that fsync(2) system call in glusterfs client code leaks memor...
vendor_debian·2018·CVSS 5.3
CVE-2018-10924 [MEDIUM] CVE-2018-10924: glusterfs - It was discovered that fsync(2) system call in glusterfs client code leaks memor...
It was discovered that fsync(2) system call in glusterfs client code leaks memory. An authenticated attacker could use this flaw to launch a denial of service attack by making gluster clients consume memory of the host machine.
Scope: local
bookworm: resolved (fixed in 4.0.1-1)
bullseye: resolved (fixed in 4.0.1-1)
forky: resolved (fixed in 4.0.1-1)
sid: resolved (fixed in 4.0.1-1)
trixie: resolved (fixed in 4.0.1-1)
GHSA
GHSA-cjxq-5pxf-g82j: It was discovered that fsync(2) system call in glusterfs client code leaks memory
ghsa_unreviewed·2022-05-13
CVE-2018-10924 [MEDIUM] CWE-772 GHSA-cjxq-5pxf-g82j: It was discovered that fsync(2) system call in glusterfs client code leaks memory
It was discovered that fsync(2) system call in glusterfs client code leaks memory. An authenticated attacker could use this flaw to launch a denial of service attack by making gluster clients consume memory of the host machine.
OSV
glusterfs vulnerabilities
osv·2021-03-15·CVSS 5.0
CVE-2014-3619 [MEDIUM] glusterfs vulnerabilities
glusterfs vulnerabilities
It was discovered that GlusterFS incorrectly handled network requests. An
attacker could possibly use this issue to cause a denial of service. This issue
only affected Ubuntu 14.04 ESM. (CVE-2014-3619)
It was discovered that GlusterFS incorrectly handled user permissions. An
authenticated attacker could possibly use this to add himself to a trusted
storage pool and perform privileged operations on volumes. This issue only
affected Ubuntu 16.04 ESM and Ubuntu 18.04 ESM. (CVE-2018-10841)
It was discovered that GlusterFS incorrectly handled mounting gluster
volumes. An attacker could possibly use this issue to also mount shared
gluster volumes and escalate privileges through malicious cronjobs. This
issue only affected Ubuntu 16.04 ESM and Ubuntu 18.04 ESM. (CVE-2
OSV
CVE-2018-10924: It was discovered that fsync(2) system call in glusterfs client code leaks memory
osv·2018-09-04·CVSS 6.5
CVE-2018-10924 [MEDIUM] CVE-2018-10924: It was discovered that fsync(2) system call in glusterfs client code leaks memory
It was discovered that fsync(2) system call in glusterfs client code leaks memory. An authenticated attacker could use this flaw to launch a denial of service attack by making gluster clients consume memory of the host machine.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-10924 glusterfs: Denial-of-service via fsync(2) in Gluster FUSE client [fedora-all]
bugzilla·2018-09-04·CVSS 5.3
CVE-2018-10924 [MEDIUM] CVE-2018-10924 glusterfs: Denial-of-service via fsync(2) in Gluster FUSE client [fedora-all]
CVE-2018-10924 glusterfs: Denial-of-service via fsync(2) in Gluster FUSE client [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple sup
Bugzilla
CVE-2018-10924 glusterfs: Denial-of-service via fsync(2) in Gluster FUSE client
bugzilla·2018-08-02·CVSS 5.3
CVE-2018-10924 [MEDIUM] CVE-2018-10924 glusterfs: Denial-of-service via fsync(2) in Gluster FUSE client
CVE-2018-10924 glusterfs: Denial-of-service via fsync(2) in Gluster FUSE client
A flaw was found in Gluster 3.12.11 and 3.12.12 FUSE client. The fsync(2) system call appears to directly or indirectly leak memory in "gf_common_mt_memdup" and "gf_common_mt_char" functions. An attacker could exploit this vulnerablity to perform a Denial of Service attack.
Discussion:
Acknowledgments:
Name: Michael Hanselmann (hansmi.ch)
---
This memory leak does not appear to be reproducible on glusterfs-3.8.x. The FUSE interface changed significantly between 3.8 and 3.12.
---
Created glusterfs tracking bugs for this issue:
Affects: fedora-all [bug 1625078]
---
upstream fix:
https://review.gluster.org/20723
---
Statement:
This issue did not affect the versions of glusterfs as shipped with Red H
http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00035.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10924https://review.gluster.org/#/c/glusterfs/+/20723/https://security.gentoo.org/glsa/201904-06http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00035.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10924https://review.gluster.org/#/c/glusterfs/+/20723/https://security.gentoo.org/glsa/201904-06
2018-09-04
Published