Vulnerability Description
A flaw was found in RPC request using gfs3_symlink_req in glusterfs server which allows symlink destinations to point to file paths outside of the gluster volume. An authenticated attacker could use this flaw to create arbitrary symlinks pointing anywhere on the server and execute arbitrary code on glusterfs server nodes.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Debian | Debian Linux | 8.0 |
| Redhat | Enterprise Linux | 6.0 |
| Redhat | Enterprise Linux Server | 6.0 |
| Gluster | Glusterfs | >= 3.12, < 3.12.14 |
| Redhat | Gluster Storage | 3.0 |
| Redhat | Virtualization Host | 4.0 |
| Opensuse | Leap | 15.1 |
Related Weaknesses (CWE)
References
- http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00035.htmlMailing ListThird Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2607Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2608Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:3470Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10928Issue TrackingPatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/09/msg00021.htmlMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/11/msg00000.htmlMailing ListThird Party Advisory
- https://security.gentoo.org/glsa/201904-06Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00035.htmlMailing ListThird Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2607Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2608Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:3470Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10928Issue TrackingPatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/09/msg00021.htmlMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/11/msg00000.htmlMailing ListThird Party Advisory
FAQ
What is CVE-2018-10928?
CVE-2018-10928 is a vulnerability with a CVSS score of 8.8 (HIGH). A flaw was found in RPC request using gfs3_symlink_req in glusterfs server which allows symlink destinations to point to file paths outside of the gluster volume. An authenticated attacker could use t...
How severe is CVE-2018-10928?
CVE-2018-10928 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-10928?
Check the references section above for vendor advisories and patch information. Affected products include: Debian Debian Linux, Redhat Enterprise Linux, Redhat Enterprise Linux Server, Gluster Glusterfs, Redhat Gluster Storage.