ZeroHour

CVE-2018-10923

CVSS 3.1
8.1 high
EPSS
2%p75
Published
()
Modified
Description

It was found that the "mknod" call derived from mknod(2) can create files pointing to devices on a glusterfs server node. An authenticated attacker could use this to create an arbitrary device and read data from any device attached to the glusterfs server node.

Vendors
glusterredhatdebianopensuse
Products
glusterfs, virtualization host, debian linux, enterprise linux server, leap
Weakness
CWE-20
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.