Severity
6.5MEDIUM
EPSS
1.6%
top 18.30%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 1
Latest updateMay 13

Description

A flaw was found in glusterfs server through versions 4.1.4 and 3.1.2 which allowed repeated usage of GF_META_LOCK_KEY xattr. A remote, authenticated attacker could use this flaw to create multiple locks for single inode by using setxattr repetitively resulting in memory exhaustion of glusterfs server node.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages6 packages

Debianglusterfs< 5.1-1+3
NVDgluster/glusterfs3.1.03.1.2+1
CVEListV5[unknown]/glusterfsaffected versions through 3.1.2, affected versions through 4.1.4+1

Also affects: Debian Linux 9.0

🔴Vulnerability Details

3
GHSA
GHSA-p6w5-mv25-26mv: A flaw was found in glusterfs server through versions 42022-05-13
OSV
CVE-2018-14660: A flaw was found in glusterfs server through versions 42018-11-01
CVEList
CVE-2018-14660: A flaw was found in glusterfs server through versions 42018-11-01

📋Vendor Advisories

3
Ubuntu
GlusterFS vulnerabilities2021-03-15
Red Hat
glusterfs: Repeat use of "GF_META_LOCK_KEY" xattr allows for memory exhaustion2018-10-31
Debian
CVE-2018-14660: glusterfs - A flaw was found in glusterfs server through versions 4.1.4 and 3.1.2 which allo...2018

💬Community

5
Bugzilla
CVE-2018-14660 glusterfs: Repeat use of "GF_META_LOCK_KEY" xattr allows for memory exhaustion [fedora-all]2018-11-08
Bugzilla
CVE-2018-14660 glusterfs: Repeat use of "GF_META_LOCK_KEY" xattr allows for memory exhaustion [fedora-all]2018-11-08
Bugzilla
CVE-2018-14660 glusterfs: Repeat use of "GF_META_LOCK_KEY" xattr allows for memory exhaustion [fedora-all]2018-10-31
Bugzilla
CVE-2018-14660 glusterfs: Repeat use of "GF_META_LOCK_KEY" xattr allows for memory exhaustion [fedora-all]2018-10-31
Bugzilla
CVE-2018-14660 glusterfs: Repeat use of "GF_META_LOCK_KEY" xattr allows for memory exhaustion2018-10-04