cbcvebase.
CVE-2018-10906
published 2018-07-24

CVE-2018-10906: In fuse before versions 2.9.8 and 3.x before 3.2.5, fusermount is vulnerable to a restriction bypass when SELinux is active. This allows non-root users to…

high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
EXPLOIT
In fuse before versions 2.9.8 and 3.x before 3.2.5, fusermount is vulnerable to a restriction bypass when SELinux is active. This allows non-root users to mount a FUSE file system with the 'allow_other' mount option regardless of whether 'user_allow_other' is set in the fuse configuration. An attacker may use this flaw to mount a FUSE file system, accessible by other users, and trick them into accessing files on that file system, possibly causing Denial of Service or other unspecified effects.

Affected

35 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debianfuse< fuse 2.9.8-1 (bookworm)fuse 2.9.8-1 (bookworm)
debianfuse3< fuse 2.9.8-1 (bookworm)fuse 2.9.8-1 (bookworm)
fuse_projectfuse< 2.9.82.9.8
fuse_projectfuse>= 3.0 < 3.2.53.2.5
msrcazl3_fuse_2.9.7-10_on_azure_linux_3.0
msrccbl2_fuse_2.9.7-10_on_cbl_mariner_2.0
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64
msrccm1_fuse_2.9.7-7_on_cbl_mariner_1.0
msrcfuse-2.9.7-10.azl3.aarch64.rpm_on_azure_linux_3.0_arm
msrcfuse-2.9.7-10.azl3.x86_64.rpm_on_azure_linux_3.0_x64
msrcfuse-2.9.7-10.cm2.aarch64.rpm_on_cbl_mariner_2.0_arm
msrcfuse-2.9.7-10.cm2.x86_64.rpm_on_cbl_mariner_2.0_x64
msrcfuse-2.9.7-7.cm1.aarch64.rpm_on_cbl_mariner_1.0_arm
msrcfuse-2.9.7-7.cm1.x86_64.rpm_on_cbl_mariner_1.0_x64
msrcfuse-debuginfo-2.9.7-10.cm2.aarch64.rpm_on_cbl_mariner_2.0_arm
msrcfuse-debuginfo-2.9.7-10.cm2.x86_64.rpm_on_cbl_mariner_2.0_x64
msrcfuse-debuginfo-2.9.7-7.cm1.aarch64.rpm_on_cbl_mariner_1.0_arm
msrcfuse-debuginfo-2.9.7-7.cm1.x86_64.rpm_on_cbl_mariner_1.0_x64
msrcfuse-devel-2.9.7-10.azl3.aarch64.rpm_on_azure_linux_3.0_arm
msrcfuse-devel-2.9.7-10.azl3.x86_64.rpm_on_azure_linux_3.0_x64

CVSS provenance

nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH