CVE-2018-10924
Last modified
CVE-2018-10924 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. It was discovered that fsync(2) system call in glusterfs client code leaks memory. An authenticated attacker could use this flaw to launch a denial of service attack by making gluster clients consume memory of the host machine.. EPSS estimates a 1.88% chance of exploitation in the next 30 days.
Description
It was discovered that fsync(2) system call in glusterfs client code leaks memory. An authenticated attacker could use this flaw to launch a denial of service attack by making gluster clients consume memory of the host machine.
Metrics
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Gluster | Glusterfs | >= 3.12.11, < 3.12.14 |
| Gluster | Glusterfs | >= 4.0.0, < 4.1.4 |
References
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10924Issue Tracking, Third Party Advisory
- https://review.gluster.org/#/c/glusterfs/+/20723/Patch, Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10924Issue Tracking, Third Party Advisory
- https://review.gluster.org/#/c/glusterfs/+/20723/Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-10924?
How severe is CVE-2018-10924?
How do I fix CVE-2018-10924?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-10919The Samba Active Directory LDAP server was vulnerable to an …4.3
- CVE-2018-1092The ext4_iget function in fs/ext4/inode.c in the Linux kerne…
- CVE-2018-10920Improper input validation bug in DNS resolver component of K…6.8
- CVE-2018-10921Certain input files may trigger an integer overflow in ttemb…4.3
- CVE-2018-10922An input validation flaw exists in ttembed. With a crafted i…7.5
- CVE-2018-10923It was found that the "mknod" call derived from mknod(2) can…8.1
- CVE-2018-10925It was discovered that PostgreSQL versions before 10.5, 9.6.…8.1
- CVE-2018-10926A flaw was found in RPC request using gfs3_mknod_req support…8.8
- CVE-2018-10927A flaw was found in RPC request using gfs3_lookup_req in glu…8.1
- CVE-2018-10928A flaw was found in RPC request using gfs3_symlink_req in gl…8.8
- CVE-2018-10929A flaw was found in RPC request using gfs2_create_req in glu…8.8
- CVE-2018-1093The ext4_valid_block_bitmap function in fs/ext4/balloc.c in …
Are you affected by CVE-2018-10924?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
