CVE-2018-18955
Description
In the Linux kernel 4.15.x through 4.19.x before 4.19.2, map_write() in kernel/user_namespace.c allows privilege escalation because it mishandles nested user namespaces with more than 5 UID or GID ranges. A user who has CAP_SYS_ADMIN in an affected user namespace can bypass access controls on resources outside the namespace, as demonstrated by reading /etc/shadow. This occurs because an ID transformation takes place properly for the namespaced-to-kernel direction but not for the kernel-to-namespaced direction.
EPSS (Exploit Prediction Scoring System)
EPSS (Exploit Prediction Scoring System)
Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.
EPSS Score Trend (Last 90 Days)
Incorrect Authorization
IncompleteCommon Consequences
Applicable Platforms
Linux - Broken uid/gid Mapping for Nested User …
Verified LocalLinux - Broken uid/gid Mapping for Nested User Namespaces
View Exploit Code →Linux - Nested User Namespace idmap Limit Local …
Verified LocalLinux - Nested User Namespace idmap Limit Local Privilege Escalation (Metasploit)
View Exploit Code →Linux Kernel 4.15.x < 4.19.2 - 'map_write() CAP_SYS_ADMIN' …
Linux Kernel 4.15.x < 4.19.2 - 'map_write() CAP_SYS_ADMIN' Local Privilege Escalation (cron Method)
View Exploit Code →Linux Kernel 4.15.x < 4.19.2 - 'map_write() CAP_SYS_ADMIN' …
Linux Kernel 4.15.x < 4.19.2 - 'map_write() CAP_SYS_ADMIN' Local Privilege Escalation (dbus Method)
View Exploit Code →Linux Kernel 4.15.x < 4.19.2 - 'map_write() CAP_SYS_ADMIN' …
Linux Kernel 4.15.x < 4.19.2 - 'map_write() CAP_SYS_ADMIN' Local Privilege Escalation (ldpreload Method)
View Exploit Code →Linux Kernel 4.15.x < 4.19.2 - 'map_write() CAP_SYS_ADMIN' …
Linux Kernel 4.15.x < 4.19.2 - 'map_write() CAP_SYS_ADMIN' Local Privilege Escalation (polkit Method)
View Exploit Code →Ubuntu Linux by Canonical
cpe:2.3:o:canonical:ubuntu_linux:18.10:*:*:*:*:*:*:*
Ubuntu Linux by Canonical
cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
Linux Kernel by Linux
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Ubuntu Linux by Canonical
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*