shield Security update for fuse
SUSE-SLE-SERVER-12-SP3-2018-2299


This update for fuse fixes the following security issue: - CVE-2018-10906: fusermount was vulnerable to a restriction bypass when SELinux is active. This allowed non-root users to mount a FUSE file system with the 'allow_other' mount option regardless of whether 'user_allow_other' is set in the fuse configuration. An attacker may use this flaw to mount a FUSE file system, accessible by other users, and trick them into accessing files on that file system, possibly causing Denial of Service or other unspecified effects (bsc#1101797)

  • Release Date
    Oct 18 2018
  • References
    Bugzilla: 1101797
    CVEs: CVE-2018-10906
  • Type
    security
  • Severity
    moderate

cloud_download Downloads

SUSE Linux Enterprise Server 12.3 s390x
  • Packages
    fuse
    User space File System
    2.9.3-6.3.1 lock rpm lock src
    libfuse2
    Library of FUSE, the User space File System for GNU/Linux and BSD
    2.9.3-6.3.1 lock rpm
SUSE Linux Enterprise Server 12.3 aarch64
  • Packages
    fuse
    User space File System
    2.9.3-6.3.1 lock rpm lock src
    libfuse2
    Library of FUSE, the User space File System for GNU/Linux and BSD
    2.9.3-6.3.1 lock rpm
SUSE Linux Enterprise Server for SAP Applications 12.3 ppc64le
  • Packages
    fuse
    User space File System
    2.9.3-6.3.1 lock rpm lock src
    libfuse2
    Library of FUSE, the User space File System for GNU/Linux and BSD
    2.9.3-6.3.1 lock rpm
SUSE Linux Enterprise Server 12.3 x86_64
  • Packages
    fuse
    User space File System
    2.9.3-6.3.1 lock rpm lock src
    libfuse2
    Library of FUSE, the User space File System for GNU/Linux and BSD
    2.9.3-6.3.1 lock rpm