CVE-2018-14660

medium
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

A flaw was found in glusterfs server through versions 4.1.4 and 3.1.2 which allowed repeated usage of GF_META_LOCK_KEY xattr. A remote, authenticated attacker could use this flaw to create multiple locks for single inode by using setxattr repetitively resulting in memory exhaustion of glusterfs server node.

References

https://access.redhat.com/errata/RHSA-2018:3431

https://access.redhat.com/errata/RHSA-2018:3432

https://access.redhat.com/errata/RHSA-2018:3470

https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14660

https://security.gentoo.org/glsa/201904-06

Details

Source: MITRE

Published: 2018-11-01

Updated: 2020-10-15

Type: CWE-770

Risk Information

CVSS v2

Base Score: 4

Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P

Impact Score: 2.9

Exploitability Score: 8

Severity: MEDIUM

CVSS v3

Base Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Impact Score: 3.6

Exploitability Score: 2.8

Severity: MEDIUM

Tenable Plugins

View all (6 total)

IDNameProductFamilySeverity
123580GLSA-201904-06 : GlusterFS: Multiple VulnerabilitiesNessusGentoo Local Security Checks
medium
120711Fedora 28 : glusterfs (2018-af9bd28cf1)NessusFedora Local Security Checks
medium
120641Fedora 29 : glusterfs (2018-986f0b7fb0)NessusFedora Local Security Checks
medium
118790RHEL 7 : Virtualization Manager (RHSA-2018:3470)NessusRed Hat Local Security Checks
medium
118583RHEL 7 : glusterfs (RHSA-2018:3432)NessusRed Hat Local Security Checks
high
118582RHEL 6 : glusterfs (RHSA-2018:3431)NessusRed Hat Local Security Checks
high