CVE Published: 31/10/2018 |
CVE Updated: 05/08/2024 |
CVE Year: 2018 Source: redhat |
Vendor: The Gluster Project |
Product: glusterfs Status : PUBLISHED
CVE-2018-14659 Description
The Gluster file system through versions 4.1.4 and 3.1.2 is vulnerable to a denial of service attack via use of the \'GF_XATTR_IOSTATS_DUMP_KEY\' xattr. A remote, authenticated attacker could exploit this by mounting a Gluster volume and repeatedly calling \'setxattr(2)\' to trigger a state dump and create an arbitrary number of files in the server\'s runtime directory.