CVE-2018-10924 describes a memory leak vulnerability in the glusterfs client code, specifically within the fsync(2) system call, affecting GlusterFS. An authenticated attacker can exploit this flaw to trigger a denial of service by causing gluster clients to consume excessive host memory. Rated Medium (CVSS 6.5), the attack is network-based with low complexity and requires low privileges, leading to high availability impact. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.12.11, < 3.12.14CPE matchmatch criteria | cpe:2.3:a:gluster:glusterfs:*:*:*:*:*:*:*:* | ||
>= 4.0.0, < 4.1.4CPE matchmatch criteria | cpe:2.3:a:gluster:glusterfs:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.