CVE-2018-10928

NameCVE-2018-10928
DescriptionA flaw was found in RPC request using gfs3_symlink_req in glusterfs server which allows symlink destinations to point to file paths outside of the gluster volume. An authenticated attacker could use this flaw to create arbitrary symlinks pointing anywhere on the server and execute arbitrary code on glusterfs server nodes.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub advisories/code/issues, web search, more)
ReferencesDLA-1510-1, DLA-2806-1
Debian Bugs909215

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
glusterfs (PTS)buster5.5-3fixed
bullseye9.2-1fixed
bookworm10.3-1fixed
sid10.3-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
glusterfssourcejessie3.5.2-2+deb8u4DLA-1510-1
glusterfssourcestretch3.8.8-1+deb9u1DLA-2806-1
glusterfssource(unstable)4.1.4-1909215

Notes

https://bugzilla.redhat.com/show_bug.cgi?id=1612659
https://github.com/gluster/glusterfs/commit/9ae986f18c0f251cba6bbc23eae2150a8ce0417e
When fixing this issue make sure to be complete an not open CVE-2018-14651

Search for package or bug name: Reporting problems