CVE-2018-10906
Last modified
CVE-2018-10906 is a vulnerability of currently unknown severity. In fuse before versions 2.9.8 and 3.x before 3.2.5, fusermount is vulnerable to a restriction bypass when SELinux is active. This allows non-root users to mount a FUSE file system with the 'allow_other' mount option regardless of whether 'user_allow_other' is set in the fuse configuration. EPSS estimates a 1.41% chance of exploitation in the next 30 days.
Description
In fuse before versions 2.9.8 and 3.x before 3.2.5, fusermount is vulnerable to a restriction bypass when SELinux is active. This allows non-root users to mount a FUSE file system with the 'allow_other' mount option regardless of whether 'user_allow_other' is set in the fuse configuration. An attacker may use this flaw to mount a FUSE file system, accessible by other users, and trick them into accessing files on that file system, possibly causing Denial of Service or other unspecified effects.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Debian | Debian Linux | 8.0 |
| Debian | Debian Linux | 9.0 |
| Fuse Project | Fuse | < 2.9.8 |
| Fuse Project | Fuse | >= 3.0, < 3.2.5 |
| Redhat | Enterprise Linux Desktop | 7.0 |
| Redhat | Enterprise Linux Server | 7.0 |
| Redhat | Enterprise Linux Workstation | 7.0 |
References
- https://access.redhat.com/errata/RHSA-2018:3324Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10906Issue Tracking, Patch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/08/msg00015.htmlMailing List, Third Party Advisory
- https://www.debian.org/security/2018/dsa-4257Third Party Advisory
- https://www.exploit-db.com/exploits/45106/Exploit, Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2018:3324Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10906Issue Tracking, Patch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/08/msg00015.htmlMailing List, Third Party Advisory
- https://www.debian.org/security/2018/dsa-4257Third Party Advisory
- https://www.exploit-db.com/exploits/45106/Exploit, Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-10906?
How severe is CVE-2018-10906?
How do I fix CVE-2018-10906?
Are you affected by CVE-2018-10906?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
