Database/Control plane, storage & DevOps
GlusterFS (brick, gfs3_mknod_req): A crafted mknod RPC traverses out of the volume and writes a file anywhere the brick
Impact
A crafted mknod RPC traverses out of the volume and writes a file anywhere the brick process can reach on the server node, which leads to code execution on the storage server. From a mounted volume, one tenant reaches the host filesystem underneath every tenant's data.
Who can reach it
Any authenticated gluster client that can mount a volume and issue RPCs to a brick - i.e. any tenant compute node with the share mounted.
What to do
Upgrade glusterfs server to the fixed release (and apply CVE-2018-14651, the follow-up that completes this fix) and restart the brick processes. Run bricks as a non-root user where your deployment supports it and keep brick ports off tenant-routable networks.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.