Vulnerability Details CVE-2018-14660
A flaw was found in glusterfs server through versions 4.1.4 and 3.1.2 which allowed repeated usage of GF_META_LOCK_KEY xattr. A remote, authenticated attacker could use this flaw to create multiple locks for single inode by using setxattr repetitively resulting in memory exhaustion of glusterfs server node.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.018
EPSS Ranking 81.7%
CVSS Severity
CVSS v3 Score 6.5
CVSS v2 Score 4.0
Products affected by CVE-2018-14660
-
cpe:2.3:a:gluster:glusterfs:3.1.0
-
cpe:2.3:a:gluster:glusterfs:3.1.1
-
cpe:2.3:a:gluster:glusterfs:3.1.2
-
cpe:2.3:a:gluster:glusterfs:4.1.0
-
cpe:2.3:a:gluster:glusterfs:4.1.1
-
cpe:2.3:a:gluster:glusterfs:4.1.2
-
cpe:2.3:a:gluster:glusterfs:4.1.3
-
cpe:2.3:a:gluster:glusterfs:4.1.4
-
cpe:2.3:a:redhat:virtualization:4.0
-
cpe:2.3:a:redhat:virtualization_host:4.0
-
cpe:2.3:o:debian:debian_linux:9.0
-
cpe:2.3:o:redhat:enterprise_linux:7.0
-
cpe:2.3:o:redhat:enterprise_linux_server:6.0
-
cpe:2.3:o:redhat:enterprise_linux_server:7.0