Database/Control plane, storage & DevOps
GlusterFS (brick, gfs3_symlink_req): Symlink creation is not confined to the volume, so a client plants a link pointing
CVE-2018-10928Control plane, storage & DevOpscurated
Impact
Symlink creation is not confined to the volume, so a client plants a link pointing at a path on the server outside the gluster tree and then reads or writes through it. That reaches other volumes and the server's own filesystem from inside one tenant's mount.
Who can reach it
Any authenticated gluster client with a mounted volume.
What to do
Upgrade glusterfs server and restart the bricks, including the CVE-2018-14651 follow-up patch. Verify no residual symlinks pointing outside the brick roots survive the upgrade.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.