CVE Database
/

CVE-2018-18955

Back to search

CVE-2018-18955

Published: Nov 16, 2018

Modified: Aug 5, 2024

PUBLISHED

Description

In the Linux kernel 4.15.x through 4.19.x before 4.19.2, map_write() in kernel/user_namespace.c allows privilege escalation because it mishandles nested user namespaces with more than 5 UID or GID ranges. A user who has CAP_SYS_ADMIN in an affected user namespace can bypass access controls on resources outside the namespace, as demonstrated by reading /etc/shadow. This occurs because an ID transformation takes place properly for the namespaced-to-kernel direction but not for the kernel-to-namespaced direction.

VendorProductVersions

n/a

n/a

affected
n/a

References

USN-3836-2
vendor-advisory
x_refsource_UBUNTU
USN-3835-1
vendor-advisory
x_refsource_UBUNTU
USN-3833-1
vendor-advisory
x_refsource_UBUNTU
USN-3832-1
vendor-advisory
x_refsource_UBUNTU
45915
exploit
x_refsource_EXPLOIT-DB
45886
exploit
x_refsource_EXPLOIT-DB
USN-3836-1
vendor-advisory
x_refsource_UBUNTU
105941
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now