Database/Control plane, storage & DevOps
GlusterFS (brick, mknod): Mknod can create device nodes that point at real devices on the storage server, so a client
Impact
Mknod can create device nodes that point at real devices on the storage server, so a client creates a block-device node inside the volume and reads raw disk. That bypasses the file layer entirely and exposes every tenant's data sitting on the same physical device.
Who can reach it
Any authenticated gluster client that can mount a volume and call mknod.
What to do
Upgrade glusterfs server and restart the bricks. Mount client-side with nodev where the workload allows, and confirm the brick process is not running with the capabilities needed to open raw devices.
References
Related entries
- HashiCorp Vault: GCP secrets engine drops existing IAM Conditions when creating/updating rolesetsCVE-2023-5077 · HashiCorp VaultHigh
- NetApp ONTAP 9 role-based access control: A user holding several remote accounts with different roles performs actionsCVE-2024-21985 · NetApp ONTAP 9 role-based access controlHigh
- HashiCorp Nomad Enterprise: Jobs using the policy-override option bypass mandatory Sentinel policiesCVE-2025-3744 · HashiCorp Nomad EnterpriseHigh
- Grafana: Client path traversal + open redirectCVE-2025-4123 · GrafanaHigh
- Sidero Omni: Reader role can read the full CA secrets bundle of an imported Talos clusterCVE-2026-45726 · Sidero Omni (ImportedClusterSecrets resource access rules)High
- rsync SSL modes: server TLS certificates are not validated, so an on-path attacker can read the transferCVE-2026-70454 · rsync (openssl mode) and rsync-ssl (stunnel mode) TLS server certificate validationHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.