CVE-2018-14654: Debian Linux
Medium severity, CVSS 6.5. EPSS: 2.6% chance of exploitation in the next 30 days.
The Gluster file system through version 4.1.4 is vulnerable to abuse of the 'features/index' translator. A remote attacker with access to mount volumes could exploit this via the 'GF_XATTROP_ENTRY_IN_KEY' xattrop to create arbitrary, empty files on the target server.
Affected products
- Debian Debian Linux: version 9.0 only
- Red Hat Enterprise Linux Server: version 6.0 only; version 7.0 only
- Red Hat Enterprise Linux Virtualization: version 4.0 only
- Red Hat Gluster Storage: up to and including 4.1.4
- Red Hat Virtualization: version 4.0 only
- Red Hat Virtualization Host: version 4.0 only
Published 2018-10-31. Last modified 2026-06-17.