Database/Control plane, storage & DevOps
OpenZFS (sharenfs export generation): When an NFS share is exported to IPv6 addresses via sharenfs, OpenZFS silently
Impact
When an NFS share is exported to IPv6 addresses via sharenfs, OpenZFS silently fails to parse the address and exports the dataset to everyone instead. The operator sees a restriction in the config that does not exist on the wire, so any host on the network mounts the dataset.
Who can reach it
Any host that can reach the NFS server, on any ZFS dataset whose sharenfs restriction was written with IPv6 addresses.
What to do
Upgrade OpenZFS past 2.0.3 and re-export the datasets, then verify the actual export list with exportfs -v rather than trusting the sharenfs property. Prefer expressing restrictions in /etc/exports directly, and audit any dataset that was shared with an IPv6 restriction.
References
Related entries
- Ceph CephX authentication protocol: An attacker who sniffs the storage network can replay a CephX authenticationCVE-2018-1128 · Ceph CephX authentication protocolHigh
- Emerson/Vertiv Liebert IntelliSlot Web Card (config/configUser.htm, config/configTelnet.htm): The IntelliSlot cardCVE-2018-12922 · Emerson/Vertiv Liebert IntelliSlot Web Card (config/configUser.htm, config/configTelnet.htm)High
- ntpd (protocol engine, zero-origin timestamp): Continually sending packets with a zero-origin timestamp lets a remoteCVE-2018-7185 · ntpd (protocol engine, zero-origin timestamp)High
- Ceph RADOS Gateway (RGW, Beast frontend): An unauthenticated client can crash radosgw by sending valid headers followedCVE-2019-10222 · Ceph RADOS Gateway (RGW, Beast frontend)High
- Slurm (srun --uid): Srun --uid drops privileges in the wrong order, so a step launched through it can end up runningCVE-2019-19728 · Slurm (srun --uid)High
- Lustre ptlrpc / mdt modules (client-driven server panic family): The head of a family of ten Lustre defectsCVE-2019-20423 · Lustre ptlrpc / mdt modules (client-driven server panic family)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.