CVE-2018-18955
HighIn the Linux kernel 4.15.x through 4.19.x before 4.19.2, map_write() in kernel/user_namespace.c allows privilege escalation because it mishandles nested user namespaces with more than 5 UID or GID ranges. A user who has CAP_SYS_ADMIN in an affected user namespace can bypass access controls on resources outside the namespace, as demonstrated by reading /etc/shadow. This occurs because an ID transformation takes place properly for the namespaced-to-kernel direction but not for the kernel-to-namespaced direction.
CVSS 3.0 score
7.0
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness type
CWE-863CVE-2018-18955 is classified as CWE-863
See CWE-863 on MITRE CWE for full details on this weakness type.
References
The following references provide additional information about CVE-2018-18955 including vendor advisories, patch commits, exploit details, and third-party analysis. Links are sourced from the NIST NVD database.
-
Securityfocushttp://www.securityfocus.com/bid/105941Third Party Advisory VDB Entry
-
-
-
Ubuntu Securityhttps://usn.ubuntu.com/3832-1/Third Party Advisory
-
Ubuntu Securityhttps://usn.ubuntu.com/3833-1/Third Party Advisory
-
Ubuntu Securityhttps://usn.ubuntu.com/3835-1/Third Party Advisory
-
Ubuntu Securityhttps://usn.ubuntu.com/3836-1/Third Party Advisory
-
Ubuntu Securityhttps://usn.ubuntu.com/3836-2/Third Party Advisory
-
Exploit-DBhttps://www.exploit-db.com/exploits/45915/Exploit Third Party Advisory VDB Entry
-
PatchKernel patch commithttp://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=d2f007dbe7e4c9583eea6eb04d60001e85c6f1bd
-
PatchKernel patch commithttps://bugs.chromium.org/p/project-zero/issues/detail?id=1712
-
PatchKernel patch commithttps://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.18.19
Frequently asked questions
-
What is CVE-2018-18955?
CVE-2018-18955 is a High severity Linux kernel vulnerability with a CVSS score of 7.0 out of 10 . CVE-2018-18955 has not been confirmed as actively exploited and is not listed in the CISA KEV catalog.
-
What is the CVSS score for CVE-2018-18955?
CVE-2018-18955 has a CVSS score of 7.0 out of 10, rated High severity (CVSS 3.0). The vector string is
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H. -
Is there a patch available for CVE-2018-18955?
No patch is currently available for CVE-2018-18955. Monitor the NIST NVD and your Linux distribution's security advisories for updates.
-
Is CVE-2018-18955 actively exploited?
No — CVE-2018-18955 has not been confirmed as actively exploited. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.