CVE-2018-10906
Summary
| CVE | CVE-2018-10906 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-07-24 20:29:00 UTC |
| Updated | 2023-11-07 02:51:00 UTC |
| Description | In fuse before versions 2.9.8 and 3.x before 3.2.5, fusermount is vulnerable to a restriction bypass when SELinux is active. This allows non-root users to mount a FUSE file system with the 'allow_other' mount option regardless of whether 'user_allow_other' is set in the fuse configuration. An attacker may use this flaw to mount a FUSE file system, accessible by other users, and trick them into accessing files on that file system, possibly causing Denial of Service or other unspecified effects. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| fusermount - user_allow_other Restriction Bypass and SELinux Label Control - Linux dos Exploit |
EXPLOIT-DB |
www.exploit-db.com |
Exploit, Third Party Advisory, VDB Entry |
| [SECURITY] Fedora 30 Update: fuse-2.9.9-1.fc30 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| Debian -- Security Information -- DSA-4257-1 fuse |
DEBIAN |
www.debian.org |
Third Party Advisory |
| 1602996 – (CVE-2018-10906) CVE-2018-10906 fuse: bypass of the "user_allow_other" restriction when SELinux is active |
CONFIRM |
bugzilla.redhat.com |
Issue Tracking, Patch, Third Party Advisory |
| [SECURITY] Fedora 28 Update: fuse-2.9.9-1.fc28 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 30 Update: fuse-2.9.9-1.fc30 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 29 Update: fuse-2.9.9-1.fc29 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 28 Update: fuse-2.9.9-1.fc28 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] [DLA 1468-1] fuse security update |
MLIST |
lists.debian.org |
Mailing List, Third Party Advisory |
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
Third Party Advisory |
| [SECURITY] Fedora 29 Update: fuse-2.9.9-1.fc29 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 500194 Alpine Linux Security Update for fuse
- 500357 Alpine Linux Security Update for fuse3
- 503935 Alpine Linux Security Update for fuse
- 503936 Alpine Linux Security Update for fuse3
- 900086 CBL-Mariner Linux Security Update for fuse 2.9.7
- 901022 Common Base Linux Mariner (CBL-Mariner) Security Update for fuse (6430-1)
- 902955 Common Base Linux Mariner (CBL-Mariner) Security Update for fuse (1867)