Name | CVE-2018-10928 |
Description | A flaw was found in RPC request using gfs3_symlink_req in glusterfs server which allows symlink destinations to point to file paths outside of the gluster volume. An authenticated attacker could use this flaw to create arbitrary symlinks pointing anywhere on the server and execute arbitrary code on glusterfs server nodes. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
References | DLA-1510-1, DLA-2806-1 |
Debian Bugs | 909215 |
Vulnerable and fixed packages
The table below lists information on source packages.
Source Package | Release | Version | Status |
---|
glusterfs (PTS) | bullseye | 9.2-1 | fixed |
| bookworm | 10.3-5 | fixed |
| trixie, sid | 11.1-5 | fixed |
The information below is based on the following data on fixed versions.
Notes
https://bugzilla.redhat.com/show_bug.cgi?id=1612659
https://github.com/gluster/glusterfs/commit/9ae986f18c0f251cba6bbc23eae2150a8ce0417e
When fixing this issue make sure to be complete an not open CVE-2018-14651