Database/Control plane, storage & DevOps
GlusterFS (dht translator, dht_setxattr_mds_cbk): A use-after-free in the distributed-hash translator crashes the brick
Impact
A use-after-free in the distributed-hash translator crashes the brick process. With brick multiplexing enabled one crash takes down several volumes at once, so a single tenant can stall storage for unrelated jobs.
Who can reach it
Reachable over the network against GlusterFS 11.0 without authentication per the CVSS assessment; in practice any client that can drive setxattr traffic to a brick.
What to do
Upgrade past GlusterFS 11.0 to a release carrying the dht fix and restart the bricks. Consider disabling brick multiplexing on multi-tenant volumes so a crash is contained to one volume.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.