PT-2018-10186 · Red Hat+2 · Glusterfs+2

Amar Tumballi

+1

·

Published

2018-09-04

·

Updated

2021-03-15

·

CVE-2018-10924

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions glusterfs (affected versions not specified)
Description A memory leak was discovered in the fsync(2) system call within the glusterfs client code. This issue could be exploited by an authenticated attacker to launch a denial of service attack, causing gluster clients to consume the host machine's memory.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Missing Release of Resource after Effective Lifetime

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-10924
OPENSUSE-SU-2020:0079-1
OPENSUSE-SU-2020_0079-1
OPENSUSE-SU-2024:10794-1
USN-4770-1

Affected Products

Suse
Ubuntu
Glusterfs