• 公告ID (KylinSec-SA-2022-1096)

摘要:

In fuse before versions 2.9.8 and 3.x before 3.2.5, fusermount is vulnerable to a restriction bypass when SELinux is active. This allows non-root users to mount a FUSE file system with the 'allow_other' mount option regardless of whether 'user_allow_other' is set in the fuse configuration. An attacker may use this flaw to mount a FUSE file system, accessible by other users, and trick them into accessing files on that file system, possibly causing Denial of Service or other unspecified effects.

安全等级: Low

公告ID: KylinSec-SA-2022-1096

发布日期: 2022年2月24日

关联CVE: CVE-2018-10906  

  • 详细介绍

1. 漏洞描述

   

In fuse before versions 2.9.8 and 3.x before 3.2.5, fusermount is vulnerable to a restriction bypass when SELinux is active. This allows non-root users to mount a FUSE file system with the 'allow_other' mount option regardless of whether 'user_allow_other' is set in the fuse configuration. An attacker may use this flaw to mount a FUSE file system, accessible by other users, and trick them into accessing files on that file system, possibly causing Denial of Service or other unspecified effects.

2. 影响范围

cve名称 产品 组件 是否受影响
CVE-2018-10906 KY3.4-4A fuse Unaffected
CVE-2018-10906 KY3.4-5 fuse Unaffected

3. 影响组件

    无

4. 修复版本

    无

5. 修复方法

   无

6. 下载链接

    无
上一篇:KylinSec-SA-2022-1095 下一篇:KylinSec-SA-2022-1097