CVE-2018-10906
published 2018-07-24CVE-2018-10906: In fuse before versions 2.9.8 and 3.x before 3.2.5, fusermount is vulnerable to a restriction bypass when SELinux is active. This allows non-root users to…
PriorityP343high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
EXPLOIT
EPSS
1.41%
69.6th percentile
In fuse before versions 2.9.8 and 3.x before 3.2.5, fusermount is vulnerable to a restriction bypass when SELinux is active. This allows non-root users to mount a FUSE file system with the 'allow_other' mount option regardless of whether 'user_allow_other' is set in the fuse configuration. An attacker may use this flaw to mount a FUSE file system, accessible by other users, and trick them into accessing files on that file system, possibly causing Denial of Service or other unspecified effects.
Affected
35 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | fuse | < fuse 2.9.8-1 (bookworm) | fuse 2.9.8-1 (bookworm) |
| debian | fuse3 | < fuse 2.9.8-1 (bookworm) | fuse 2.9.8-1 (bookworm) |
| fuse_project | fuse | < 2.9.8 | 2.9.8 |
| fuse_project | fuse | >= 3.0 < 3.2.5 | 3.2.5 |
| msrc | azl3_fuse_2.9.7-10_on_azure_linux_3.0 | — | — |
| msrc | cbl2_fuse_2.9.7-10_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| msrc | cm1_fuse_2.9.7-7_on_cbl_mariner_1.0 | — | — |
| msrc | fuse-2.9.7-10.azl3.aarch64.rpm_on_azure_linux_3.0_arm | — | — |
| msrc | fuse-2.9.7-10.azl3.x86_64.rpm_on_azure_linux_3.0_x64 | — | — |
| msrc | fuse-2.9.7-10.cm2.aarch64.rpm_on_cbl_mariner_2.0_arm | — | — |
| msrc | fuse-2.9.7-10.cm2.x86_64.rpm_on_cbl_mariner_2.0_x64 | — | — |
| msrc | fuse-2.9.7-7.cm1.aarch64.rpm_on_cbl_mariner_1.0_arm | — | — |
| msrc | fuse-2.9.7-7.cm1.x86_64.rpm_on_cbl_mariner_1.0_x64 | — | — |
| msrc | fuse-debuginfo-2.9.7-10.cm2.aarch64.rpm_on_cbl_mariner_2.0_arm | — | — |
| msrc | fuse-debuginfo-2.9.7-10.cm2.x86_64.rpm_on_cbl_mariner_2.0_x64 | — | — |
| msrc | fuse-debuginfo-2.9.7-7.cm1.aarch64.rpm_on_cbl_mariner_1.0_arm | — | — |
| msrc | fuse-debuginfo-2.9.7-7.cm1.x86_64.rpm_on_cbl_mariner_1.0_x64 | — | — |
| msrc | fuse-devel-2.9.7-10.azl3.aarch64.rpm_on_azure_linux_3.0_arm | — | — |
| msrc | fuse-devel-2.9.7-10.azl3.x86_64.rpm_on_azure_linux_3.0_x64 | — | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_msrc7.8HIGH
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
fuse: bypass of the "user_allow_other" restriction when SELinux is active
vendor_redhat·2018-07-24·CVSS 5.3
CVE-2018-10906 [MEDIUM] CWE-285 fuse: bypass of the "user_allow_other" restriction when SELinux is active
fuse: bypass of the "user_allow_other" restriction when SELinux is active
In fuse before versions 2.9.8 and 3.x before 3.2.5, fusermount is vulnerable to a restriction bypass when SELinux is active. This allows non-root users to mount a FUSE file system with the 'allow_other' mount option regardless of whether 'user_allow_other' is set in the fuse configuration. An attacker may use this flaw to mount a FUSE file system, accessible by other users, and trick them into accessing files on that file system, possibly causing Denial of Service or other unspecified effects.
A vulnerability was discovered in fuse. When SELinux is active, fusermount is vulnerable to a restriction bypass. This allows non-root users to mount a FUSE file system with the 'allow_other' mount option regardless of whethe
Microsoft
In fuse before versions 2.9.8 and 3.x before 3.2.5 fusermount is vulnerable to a restriction bypass when SELinux is active. This allows non-root users to mount a FUSE file system with the 'allow_other
vendor_msrc·2018-07-10·CVSS 7.8
CVE-2018-10906 [MEDIUM] CWE-269 In fuse before versions 2.9.8 and 3.x before 3.2.5 fusermount is vulnerable to a restriction bypass when SELinux is active. This allows non-root users to mount a FUSE file system with the 'allow_other
In fuse before versions 2.9.8 and 3.x before 3.2.5 fusermount is vulnerable to a restriction bypass when SELinux is active. This allows non-root users to mount a FUSE file system with the 'allow_other' mount option regardless of whether 'user_allow_other' is set in the fuse configuration. An attacker may use this flaw to mount a FUSE file system accessible by other users and trick them into accessing files on that file system possibly causing Denial of Service or other unspecified effects.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secu
Debian
CVE-2018-10906: fuse - In fuse before versions 2.9.8 and 3.x before 3.2.5, fusermount is vulnerable to ...
vendor_debian·2018·CVSS 5.3
CVE-2018-10906 [MEDIUM] CVE-2018-10906: fuse - In fuse before versions 2.9.8 and 3.x before 3.2.5, fusermount is vulnerable to ...
In fuse before versions 2.9.8 and 3.x before 3.2.5, fusermount is vulnerable to a restriction bypass when SELinux is active. This allows non-root users to mount a FUSE file system with the 'allow_other' mount option regardless of whether 'user_allow_other' is set in the fuse configuration. An attacker may use this flaw to mount a FUSE file system, accessible by other users, and trick them into accessing files on that file system, possibly causing Denial of Service or other unspecified effects.
Scope: local
bookworm: resolved (fixed in 2.9.8-1)
bullseye: resolved (fixed in 2.9.8-1)
sid: resolved (fixed in 2.9.8-1)
trixie: resolved (fixed in 2.9.8-1)
GHSA
GHSA-35h9-x59q-8xcf: In fuse before versions 2
ghsa_unreviewed·2022-05-13
CVE-2018-10906 [HIGH] CWE-269 GHSA-35h9-x59q-8xcf: In fuse before versions 2
In fuse before versions 2.9.8 and 3.x before 3.2.5, fusermount is vulnerable to a restriction bypass when SELinux is active. This allows non-root users to mount a FUSE file system with the 'allow_other' mount option regardless of whether 'user_allow_other' is set in the fuse configuration. An attacker may use this flaw to mount a FUSE file system, accessible by other users, and trick them into accessing files on that file system, possibly causing Denial of Service or other unspecified effects.
OSV
CVE-2018-10906: In fuse before versions 2
osv·2018-07-24·CVSS 7.8
CVE-2018-10906 [HIGH] CVE-2018-10906: In fuse before versions 2
In fuse before versions 2.9.8 and 3.x before 3.2.5, fusermount is vulnerable to a restriction bypass when SELinux is active. This allows non-root users to mount a FUSE file system with the 'allow_other' mount option regardless of whether 'user_allow_other' is set in the fuse configuration. An attacker may use this flaw to mount a FUSE file system, accessible by other users, and trick them into accessing files on that file system, possibly causing Denial of Service or other unspecified effects.
No detection rules found.
Bugzilla
CVE-2018-10906 fuse: bypass of the "user_allow_other" restriction when SELinux is active [fedora-all]
bugzilla·2018-07-24·CVSS 5.3
CVE-2018-10906 [MEDIUM] CVE-2018-10906 fuse: bypass of the "user_allow_other" restriction when SELinux is active [fedora-all]
CVE-2018-10906 fuse: bypass of the "user_allow_other" restriction when SELinux is active [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects mul
Bugzilla
CVE-2018-10906 fuse: bypass of the "user_allow_other" restriction when SELinux is active
bugzilla·2018-07-19·CVSS 5.3
CVE-2018-10906 [MEDIUM] CVE-2018-10906 fuse: bypass of the "user_allow_other" restriction when SELinux is active
CVE-2018-10906 fuse: bypass of the "user_allow_other" restriction when SELinux is active
FUSE through version 3.2.4 is vulnerable to a bypass of the 'user_allow_other'
restriction that allows, when SELinux is active, non-root users to mount FUSE
file systems with the 'allow_other' mount option. Local users can exploit this
with the 'fusermount' command, bypassing the system configuration. This results
in a mounted file system accessible by all other users including root.
Discussion:
This flaw allows a local attacker to mount a FUSE file system with the
'allow_other' option, even if they should not be able to do so. As a
consequence, if the attacker can trick other users to access his FUSE mount
point, he can cause Denial of Services or other unspecified effects. Accesses to
the FUSE mou
https://access.redhat.com/errata/RHSA-2018:3324https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10906https://lists.debian.org/debian-lts-announce/2018/08/msg00015.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5XYA6PXT5PPWVK7CM7K4YRCYWA37DODB/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/A253TZWZK6R7PT2S5JIEAQJR2TYKX7V2/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BREAIWIK64DRJWHIGR47L2D5YICY4HQ3/https://www.debian.org/security/2018/dsa-4257https://www.exploit-db.com/exploits/45106/https://access.redhat.com/errata/RHSA-2018:3324https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10906https://lists.debian.org/debian-lts-announce/2018/08/msg00015.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5XYA6PXT5PPWVK7CM7K4YRCYWA37DODB/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/A253TZWZK6R7PT2S5JIEAQJR2TYKX7V2/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BREAIWIK64DRJWHIGR47L2D5YICY4HQ3/https://www.debian.org/security/2018/dsa-4257https://www.exploit-db.com/exploits/45106/
2018-07-24
Published