VYPR
High severity8.1NVD Advisory· Published Sep 4, 2018· Updated Jun 17, 2026

CVE-2018-10923

CVE-2018-10923

Description

It was found that the "mknod" call derived from mknod(2) can create files pointing to devices on a glusterfs server node. An authenticated attacker could use this to create an arbitrary device and read data from any device attached to the glusterfs server node.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

10
  • Gluster/Glusterfs2 versions
    cpe:2.3:a:gluster:glusterfs:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:gluster:glusterfs:*:*:*:*:*:*:*:*range: >=3.12.0,<3.12.14
    • (no CPE)
  • cpe:2.3:a:redhat:virtualization_host:4.0:*:*:*:*:*:*:*
  • Debian/linux2 versions
    cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
    • cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
  • cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*
  • cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*
    • cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*
  • osv-coords
    Range: < 3.12.15-lp151.3.3.1
  • Red Hat/glusterfsv5
    Range: n/a

Patches

Vulnerability mechanics

References

8

News mentions

0

No linked articles in our index yet.