GPU VulnDB

Database/Control plane, storage & DevOps

GlusterFS (brick, gfs3_mknod_req): A crafted mknod RPC traverses out of the volume and writes a file anywhere the brick

CVE-2018-10926Control plane, storage & DevOpscurated

Impact

A crafted mknod RPC traverses out of the volume and writes a file anywhere the brick process can reach on the server node, which leads to code execution on the storage server. From a mounted volume, one tenant reaches the host filesystem underneath every tenant's data.

Who can reach it

Any authenticated gluster client that can mount a volume and issue RPCs to a brick - i.e. any tenant compute node with the share mounted.

What to do

Upgrade glusterfs server to the fixed release (and apply CVE-2018-14651, the follow-up that completes this fix) and restart the brick processes. Run bricks as a non-root user where your deployment supports it and keep brick ports off tenant-routable networks.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.