Vulnerability Description
It was found that the "mknod" call derived from mknod(2) can create files pointing to devices on a glusterfs server node. An authenticated attacker could use this to create an arbitrary device and read data from any device attached to the glusterfs server node.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gluster | Glusterfs | >= 3.12.0, < 3.12.14 |
| Redhat | Virtualization Host | 4.0 |
| Debian | Debian Linux | 8.0 |
| Redhat | Enterprise Linux Server | 6.0 |
| Opensuse | Leap | 15.1 |
Related Weaknesses (CWE)
References
- http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00035.htmlMailing ListThird Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2607Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2608Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:3470Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10923Issue TrackingMitigation
- https://lists.debian.org/debian-lts-announce/2018/09/msg00021.htmlMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/11/msg00000.htmlMailing ListThird Party Advisory
- https://security.gentoo.org/glsa/201904-06Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00035.htmlMailing ListThird Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2607Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2608Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:3470Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10923Issue TrackingMitigation
- https://lists.debian.org/debian-lts-announce/2018/09/msg00021.htmlMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/11/msg00000.htmlMailing ListThird Party Advisory
FAQ
What is CVE-2018-10923?
CVE-2018-10923 is a vulnerability with a CVSS score of 8.1 (HIGH). It was found that the "mknod" call derived from mknod(2) can create files pointing to devices on a glusterfs server node. An authenticated attacker could use this to create an arbitrary device and rea...
How severe is CVE-2018-10923?
CVE-2018-10923 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-10923?
Check the references section above for vendor advisories and patch information. Affected products include: Gluster Glusterfs, Redhat Virtualization Host, Debian Debian Linux, Redhat Enterprise Linux Server, Opensuse Leap.