Multiple Inode Lock Vulnerability in GlusterFS by Red Hat
CVE-2018-14660
What is CVE-2018-14660?
A vulnerability has been identified in GlusterFS affecting versions 3.1.2 and 4.1.4. This issue arises from the improper handling of GF_META_LOCK_KEY extended attributes which allows an authenticated remote attacker to execute repeated setxattr operations. By exploiting this flaw, the attacker can create multiple locks for a single inode, leading to potential memory exhaustion of the GlusterFS server node. This could severely impact the performance and availability of the server.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
glusterfs affected versions through 4.1.4
glusterfs affected versions through 3.1.2
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
