CVE-2018-10906
Last modified
CVE-2018-10906 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. In fuse before versions 2.9.8 and 3.x before 3.2.5, fusermount is vulnerable to a restriction bypass when SELinux is active. This allows non-root users to mount a FUSE file system with the 'allow_other' mount option regardless of whether 'user_allow_other' is set in the fuse configuration. EPSS estimates a 1.41% chance of exploitation in the next 30 days.
Description
In fuse before versions 2.9.8 and 3.x before 3.2.5, fusermount is vulnerable to a restriction bypass when SELinux is active. This allows non-root users to mount a FUSE file system with the 'allow_other' mount option regardless of whether 'user_allow_other' is set in the fuse configuration. An attacker may use this flaw to mount a FUSE file system, accessible by other users, and trick them into accessing files on that file system, possibly causing Denial of Service or other unspecified effects.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Debian | Debian Linux | 8.0 |
| Debian | Debian Linux | 9.0 |
| Fuse Project | Fuse | < 2.9.8 |
| Fuse Project | Fuse | >= 3.0, < 3.2.5 |
| Redhat | Enterprise Linux Desktop | 7.0 |
| Redhat | Enterprise Linux Server | 7.0 |
| Redhat | Enterprise Linux Workstation | 7.0 |
References
- https://access.redhat.com/errata/RHSA-2018:3324Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10906Issue Tracking, Patch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/08/msg00015.htmlMailing List, Third Party Advisory
- https://www.debian.org/security/2018/dsa-4257Third Party Advisory
- https://www.exploit-db.com/exploits/45106/Exploit, Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2018:3324Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10906Issue Tracking, Patch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/08/msg00015.htmlMailing List, Third Party Advisory
- https://www.debian.org/security/2018/dsa-4257Third Party Advisory
- https://www.exploit-db.com/exploits/45106/Exploit, Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-10906?
How severe is CVE-2018-10906?
How do I fix CVE-2018-10906?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-10900Network Manager VPNC plugin (aka networkmanager-vpnc) before…7.8
- CVE-2018-10901A flaw was found in Linux kernel's KVM virtualization subsys…7.8
- CVE-2018-10902It was found that the raw midi kernel driver does not protec…7.8
- CVE-2018-10903A flaw was found in python-cryptography versions between >=1…7.5
- CVE-2018-10904It was found that glusterfs server does not properly sanitiz…8.8
- CVE-2018-10905CloudForms Management Engine (cfme) is vulnerable to an impr…7.8
- CVE-2018-10907It was found that glusterfs server is vulnerable to multiple…8.8
- CVE-2018-10908It was found that vdsm before version 4.20.37 invokes qemu-i…6.5
- CVE-2018-10909Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2018-1091In the flush_tmregs_to_thread function in arch/powerpc/kerne…
- CVE-2018-10910A bug in Bluez may allow for the Bluetooth Discoverable stat…4.5
- CVE-2018-10911A flaw was found in the way dic_unserialize function of glus…7.5
Are you affected by CVE-2018-10906?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
