CVE-2018-14654: Debian Linux

Medium severity, CVSS 6.5. EPSS: 2.6% chance of exploitation in the next 30 days.

The Gluster file system through version 4.1.4 is vulnerable to abuse of the 'features/index' translator. A remote attacker with access to mount volumes could exploit this via the 'GF_XATTROP_ENTRY_IN_KEY' xattrop to create arbitrary, empty files on the target server.

Affected products

  • Debian Debian Linux: version 9.0 only
  • Red Hat Enterprise Linux Server: version 6.0 only; version 7.0 only
  • Red Hat Enterprise Linux Virtualization: version 4.0 only
  • Red Hat Gluster Storage: up to and including 4.1.4
  • Red Hat Virtualization: version 4.0 only
  • Red Hat Virtualization Host: version 4.0 only

Published 2018-10-31. Last modified 2026-06-17.