CVE-2018-14651: Debian Linux
High severity, CVSS 8.8. EPSS: 3.2% chance of exploitation in the next 30 days.
It was found that the fix for CVE-2018-10927, CVE-2018-10928, CVE-2018-10929, CVE-2018-10930, and CVE-2018-10926 was incomplete. A remote, authenticated attacker could use one of these flaws to execute arbitrary code, create arbitrary files, or cause denial of service on glusterfs server nodes via symlinks to relative paths.
Affected products
- Debian Debian Linux: version 8.0 only
- Gluster Glusterfs: from 3.12, up to and including 3.12.14; from 4.1, up to and including 4.1.4
- Red Hat Enterprise Linux: version 6.0 only; version 7.0 only
Published 2018-10-31. Last modified 2026-06-17.