Lucene search

K
redhatcveRedhat.comRH:CVE-2018-10914
HistorySep 04, 2018 - 5:50 a.m.

CVE-2018-10914

2018-09-0405:50:02
redhat.com
access.redhat.com
7

0.017 Low

EPSS

Percentile

87.7%

It was found that an attacker could issue a xattr request via glusterfs FUSE to cause gluster brick process to crash which will result in a remote denial of service. If gluster multiplexing is enabled this will result in a crash of multiple bricks and gluster volumes.

Mitigation

SELinux mitigates this issue on Red Hat Gluster Storage 3. SELinux should be in enforcing mode only as permissive mode does not block attacks.