CVE-2018-10926: Input Validation
A flaw was found in RPC request using gfs3mknodreq supported by glusterfs server. An authenticated attacker could use this flaw to write files to an arbitrary location via path traversal and execute arbitrary code on a glusterfs server node.
Other sources
The Gluster filesystem allows for device files to be created in arbitrary locations via a mounted volume. This can be exploited by users with access to the storage server to read and write to the entire disk.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-10926?
CVE-2018-10926 is a vulnerability in the glusterfs server that allows an authenticated attacker to write files to an arbitrary location and execute arbitrary code.
Which software versions are affected by CVE-2018-10926?
GlusterFS versions up to 3.12.14 and 4.1.4 are affected by CVE-2018-10926. Redhat Enterprise Linux 6.0, 7.0, and 7.0 servers, and Redhat Virtualization Host 4.0 are also affected.
How severe is the vulnerability CVE-2018-10926?
CVE-2018-10926 has a severity score of 8.8, which is considered high.
What is the Common Weakness Enumeration (CWE) ID for CVE-2018-10926?
The Common Weakness Enumeration (CWE) IDs for CVE-2018-10926 are CWE-22 and CWE-20.
How can I fix CVE-2018-10926?
To fix CVE-2018-10926, it is recommended to update GlusterFS to version 3.12.14 or 4.1.4, or apply the appropriate patches provided by Redhat. Additionally, ensure that the system is running the latest security updates.