CVE-2018-10927
Published: 4 September 2018
A flaw was found in RPC request using gfs3_lookup_req in glusterfs server. An authenticated attacker could use this flaw to leak information and execute remote denial of service by crashing gluster brick process.
From the Ubuntu security team
It was discovered that GlusterFS incorrectly handled RPC requests. An attacker could possibly use this issue to write iles to an arbitrary location and execute arbitrary code.
Priority
CVSS 3 base score: 8.1
Status
Package | Release | Status |
---|---|---|
glusterfs Launchpad, Ubuntu, Debian |
bionic |
Needed
|
cosmic |
Ignored
(reached end-of-life)
|
|
disco |
Not vulnerable
(4.1.4-1)
|
|
eoan |
Not vulnerable
(4.1.4-1)
|
|
focal |
Not vulnerable
(4.1.4-1)
|
|
groovy |
Not vulnerable
(4.1.4-1)
|
|
hirsute |
Not vulnerable
(4.1.4-1)
|
|
impish |
Not vulnerable
(4.1.4-1)
|
|
jammy |
Not vulnerable
(4.1.4-1)
|
|
precise |
Does not exist
|
|
trusty |
Needed
|
|
upstream |
Needs triage
|
|
xenial |
Ignored
(end of standard support, was needed)
|