glusterfs: "features/index" translator can create arbitrary, empty files
Published Oct 31, 2018
6.5
MEDIUMCVSS 3.1
EPSS 2.63%
Description
The Gluster file system through version 4.1.4 is vulnerable to abuse of the 'features/index' translator. A remote attacker with access to mount volumes could exploit this via the 'GF_XATTROP_ENTRY_IN_KEY' xattrop to create arbitrary, empty files on the target server.
Affected products
-
- Version through 4.1.4StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| The Gluster Project | Glusterfs | n/a |
|
Configuration 1
- ≤ 4.1.4
Configuration 2
- 6.0
- 7.0
- 4.0
Configuration 3
- 4.0
- 4.0
Running on/with
- 7.0
Configuration 4
- 9.0
No data.
Native Client for RHEL 6 for Red Hat Storage
glusterfs-0:3.12.2-25.el6
Fixed · RHSA-2018:3431
Native Client for RHEL 7 for Red Hat Storage
glusterfs-0:3.12.2-25.el7
Fixed · RHSA-2018:3432
Red Hat Gluster Storage 3.4 for RHEL 6
glusterfs-0:3.12.2-25.el6rhs
Fixed · RHSA-2018:3431
Red Hat Gluster Storage 3.4 for RHEL 6
redhat-storage-server-0:3.4.1.0-1.el6rhs
Fixed · RHSA-2018:3431
Red Hat Gluster Storage 3.4 for RHEL 7
glusterfs-0:3.12.2-25.el7rhgs
Fixed · RHSA-2018:3432
Red Hat Gluster Storage 3.4 for RHEL 7
redhat-storage-server-0:3.4.1.0-1.el7rhgs
Fixed · RHSA-2018:3432
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7
glusterfs-0:3.12.2-25.el7
Fixed · RHSA-2018:3432
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7
imgbased-0:1.0.29-1.el7ev
Fixed · RHSA-2018:3470
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7
redhat-release-virtualization-host-0:4.2-7.3.el7
Fixed · RHSA-2018:3470
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7
redhat-virtualization-host-0:4.2-20181026.0.el7_6
Fixed · RHSA-2018:3470
Red Hat Enterprise Linux 6
glusterfs
Not affected
Red Hat Enterprise Linux 7
glusterfs
Not affected
Red Hat Enterprise Linux 8
glusterfs
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Native Client for RHEL 6 for Red Hat Storage | glusterfs-0:3.12.2-25.el6 | Fixed | RHSA-2018:3431 |
| Native Client for RHEL 7 for Red Hat Storage | glusterfs-0:3.12.2-25.el7 | Fixed | RHSA-2018:3432 |
| Red Hat Gluster Storage 3.4 for RHEL 6 | glusterfs-0:3.12.2-25.el6rhs | Fixed | RHSA-2018:3431 |
| Red Hat Gluster Storage 3.4 for RHEL 6 | redhat-storage-server-0:3.4.1.0-1.el6rhs | Fixed | RHSA-2018:3431 |
| Red Hat Gluster Storage 3.4 for RHEL 7 | glusterfs-0:3.12.2-25.el7rhgs | Fixed | RHSA-2018:3432 |
| Red Hat Gluster Storage 3.4 for RHEL 7 | redhat-storage-server-0:3.4.1.0-1.el7rhgs | Fixed | RHSA-2018:3432 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 | glusterfs-0:3.12.2-25.el7 | Fixed | RHSA-2018:3432 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 | imgbased-0:1.0.29-1.el7ev | Fixed | RHSA-2018:3470 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 | redhat-release-virtualization-host-0:4.2-7.3.el7 | Fixed | RHSA-2018:3470 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 | redhat-virtualization-host-0:4.2-20181026.0.el7_6 | Fixed | RHSA-2018:3470 |
| Red Hat Enterprise Linux 6 | glusterfs | Not affected | n/a |
| Red Hat Enterprise Linux 7 | glusterfs | Not affected | n/a |
| Red Hat Enterprise Linux 8 | glusterfs | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue did not affect Red Hat Enterprise Linux 6 and 7 as the flaw is present in glusterfs-server, which is not shipped there. This flaw affects glusterfs versions included in Red Hat Virtualization 4 Hypervisor. However, in recommended configurations, the vulnerability is only exposed to hypervisor administrators and can not be exploited from virtual machines or other hosts on the network.
References (10)
- https://access.redhat.com/errata/RHSA-2018:3431 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/errata/RHSA-2018:3432 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/errata/RHSA-2018:3470 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/security/cve/CVE-2018-14654 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1631576 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14654 x_refsource_CONFIRMIssue TrackingVendor Advisory
- https://lists.debian.org/debian-lts-announce/2021/11/msg00000.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2018-14654
- https://security.gentoo.org/glsa/201904-06 vendor-advisoryx_refsource_GENTOOThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2018-14654
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2018:3431 | vendor-advisoryx_refsource_REDHATVendor Advisory | |
| https://access.redhat.com/errata/RHSA-2018:3432 | vendor-advisoryx_refsource_REDHATVendor Advisory | |
| https://access.redhat.com/errata/RHSA-2018:3470 | vendor-advisoryx_refsource_REDHATVendor Advisory | |
| https://access.redhat.com/security/cve/CVE-2018-14654 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1631576 | Issue Tracking | |
| https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14654 | x_refsource_CONFIRMIssue TrackingVendor Advisory | |
| https://lists.debian.org/debian-lts-announce/2021/11/msg00000.html | mailing-listx_refsource_MLISTMailing ListThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2018-14654 | ||
| https://security.gentoo.org/glsa/201904-06 | vendor-advisoryx_refsource_GENTOOThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2018-14654 |
Change history (0)
No recorded changes yet.