CVE-2018-18955
HighIn the Linux kernel 4.15.x through 4.19.x before 4.19.2, map_write() in kernel/user_namespace.c allows privilege escalation because it mishandles nested user namespaces with more than 5 UID or GID ranges. A user who has CAP_SYS_ADMIN in an affected user namespace can bypass access controls on resources outside the namespace, as demonstrated by reading /etc/shadow. This occurs because an ID transformation takes place properly for the namespaced-to-kernel direction but not for the kernel-to-namespaced direction.
CVSS 3.0 score
7.0
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness type
CWE-863CVE-2018-18955 is classified as CWE-863
See CWE-863 on MITRE CWE for full details on this weakness type.
References
15 total-
Exploit-DBhttps://www.exploit-db.com/exploits/45886/Exploit Patch Third Party Advisory VDB Entry
-
Exploit-DBhttps://www.exploit-db.com/exploits/45915/Exploit Third Party Advisory VDB Entry
-
Patch Vendor Advisory
-
Patch Vendor Advisory
-
Patch Vendor Advisory
Frequently asked questions
-
What is CVE-2018-18955?
CVE-2018-18955 is a High severity Linux kernel vulnerability with a CVSS score of 7.0 out of 10 . CVE-2018-18955 has not been confirmed as actively exploited and is not listed in the CISA KEV catalog.
-
What is the CVSS score for CVE-2018-18955?
CVE-2018-18955 has a CVSS score of 7.0 out of 10, rated High severity (CVSS 3.0). The vector string is
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H. -
Is there a patch available for CVE-2018-18955?
Monitor the NIST NVD and your Linux distribution's security advisories for CVE-2018-18955 patch availability.
-
Is CVE-2018-18955 actively exploited?
No. CVE-2018-18955 has not been confirmed as actively exploited. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.