CVE Database
/

CVE-2018-13405

Back to search

CVE-2018-13405

Published: Jul 6, 2018

Modified: Aug 5, 2024

PUBLISHED

Description

The inode_init_owner function in fs/inode.c in the Linux kernel through 3.16 allows local users to create files with an unintended group ownership, in a scenario where a directory is SGID to a certain group and is writable by a user who is not a member of that group. Here, the non-member can trigger creation of a plain file whose group ownership is that group. The intended behavior was that the non-member can trigger creation of a directory (but not a plain file) whose group ownership is that group. The non-member can escalate privileges by making the plain file executable and SGID.

VendorProductVersions

n/a

n/a

affected
n/a

References

USN-3752-2
vendor-advisory
x_refsource_UBUNTU
RHSA-2018:3083
vendor-advisory
x_refsource_REDHAT
USN-3752-3
vendor-advisory
x_refsource_UBUNTU
USN-3753-2
vendor-advisory
x_refsource_UBUNTU
USN-3754-1
vendor-advisory
x_refsource_UBUNTU
RHSA-2018:2948
vendor-advisory
x_refsource_REDHAT
45033
exploit
x_refsource_EXPLOIT-DB
DSA-4266
vendor-advisory
x_refsource_DEBIAN
106503
vdb-entry
x_refsource_BID
USN-3752-1
vendor-advisory
x_refsource_UBUNTU
RHSA-2018:3096
vendor-advisory
x_refsource_REDHAT
USN-3753-1
vendor-advisory
x_refsource_UBUNTU
RHSA-2019:0717
vendor-advisory
x_refsource_REDHAT
RHSA-2019:2476
vendor-advisory
x_refsource_REDHAT
RHSA-2019:2566
vendor-advisory
x_refsource_REDHAT
RHSA-2019:2696
vendor-advisory
x_refsource_REDHAT
RHSA-2019:2730
vendor-advisory
x_refsource_REDHAT
RHSA-2019:4159
vendor-advisory
x_refsource_REDHAT
RHSA-2019:4164
vendor-advisory
x_refsource_REDHAT
FEDORA-2022-3a60c34473
vendor-advisory
x_refsource_FEDORA
FEDORA-2022-5d0676b098
vendor-advisory
x_refsource_FEDORA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now
CVE-2018-13405 - Security Vulnerability | QwikSec