CVE-2018-10914 PUBLISHED

It was found that an attacker could issue a xattr request via glusterfs FUSE to cause gluster brick process to crash which will result in a remote denial of service. If gluster multiplexing is enabled this will result in a crash of multiple bricks and gluster volumes.

EPSS 5.77% · 90.4th percentile

Risk Scores

EPSS Score
5.77%
90.4th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:18.04:LTSglusterfs3.13.2-1ubuntu1, 0, 3.11.2-1
Ubuntu:Pro:14.04:LTSglusterfs3.2.7-3ubuntu2, 3.4.1-1ubuntu1, 3.4.1-2ubuntu1
Ubuntu:Pro:16.04:LTSglusterfs3.7.3-1ubuntu1, 3.7.3-1ubuntu2, 3.7.6-1ubuntu1

Timeline

References

Open in Interactive Console →