Sploitus

CVE-2018-18955

27 known exploits for CVE-2018-18955

In the Linux kernel 4.15.x through 4.19.x before 4.19.2, map_write() in kernel/user_namespace.c allows privilege escalation because it mishandles nested user namespaces with more than 5 UID or GID ranges. A user who has CAP_SYS_ADMIN in an affected user namespace can bypass access controls on resources outside the namespace, as demonstrated by reading /etc/shadow. This occurs because an ID transformation takes place properly for the namespaced-to-kernel direction but not for the kernel-to-namespaced direction.

Affected products
Alt Linux, Linux Kernel, Ubuntu
Linux Linux Kernel
< 4.19.2
Fix
Available
CVSS 3.0
7.0 HIGH
EPSS
7.6% (94th percentile)
Weakness
CWE-863
NVD status
Modified
Published
2018-11-16
CVE-2018-18955 at NVD
Authoritative description, scoring and affected products

27 known exploits for CVE-2018-18955

Proof-of-concept code and exploit modules indexed by Sploitus

CVE-2018-18955
2026-08-28 KitPloitKITPLOIT
linux-kernel-exploits
2026-08-28 KitPloitKITPLOIT
kernel-exploits
2026-08-28 KitPloitKITPLOIT
CVE-2018-18955
2026-08-27 KitPloitKITPLOIT
Exploit for Use After Free in Linux Linux_Kernel
2025-07-27 mirrors_bcolesGITEE
Exploit for Incorrect Authorization in Linux Linux_Kernel
2022-01-19 scheatkodeGITHUB
Exploit for Use After Free in Linux Linux_Kernel
2021-09-03 VisMyLoverGITEE
Exploit for Use After Free in Linux Linux_Kernel
2020-01-14 povcfeGITEE
Linux Kernel 4.15.x < 4.19.2 - map_write() CAP_SYS_ADMIN Local Privilege Escalation Exploit
2019-07-26 bcolesZDTBash
Linux Kernel 4.15.x < 4.19.2 - map_write() CAP_SYS_ADMIN Local Privilege Escalation (cron Method)
2019-07-26 bcolesZDTBash
Linux Kernel 4.15.x < 4.19.2 - map_write() CAP_SYS_ADMIN Local Privilege Escalation (polkit)
2019-07-26 bcolesZDTBash
Linux Kernel 4.15.x < 4.19.2 - map_write() CAP_SYS_ADMIN Local Privilege Escalation (ldpreload)
2019-07-26 bcolesZDTBash
Linux Kernel 4.15.x 4.19.2 - map_write() CAP_SYS_ADMIN Local Privilege Escalation (dbus Method)
2019-01-04 bcolesEXPLOITPACKBash
Linux Kernel 4.15.x 4.19.2 - map_write() CAP_SYS_ADMIN Local Privilege Escalation (polkit Method)
2019-01-04 bcolesEXPLOITPACKBash
Linux Kernel 4.15.x < 4.19.2 - 'map_write() CAP_SYS_ADMIN' Local Privilege Escalation (polkit Method)
2019-01-04 bcolesEXPLOITDBBash
Linux Kernel 4.15.x < 4.19.2 - 'map_write() CAP_SYS_ADMIN' Local Privilege Escalation (dbus Method)
2019-01-04 bcolesEXPLOITDBBash
Linux - Nested User Namespace idmap Limit Local Privilege Escalation (Metasploit)
2018-11-29 MetasploitEXPLOITDBRuby
Linux Nested User Namespace idmap Limit Local Privilege Escalation Exploit
2018-11-28 metasploitZDTRuby
Linux Nested User Namespace idmap Limit Local Privilege Escalation
2018-11-28 Brendan ColesPACKETSTORMRuby
Linux Kernel 4.15.x 4.19.2 - map_write() CAP_SYS_ADMIN Local Privilege Escalation (ldpreload Method)
2018-11-21 bcolesEXPLOITPACKBash
Linux Kernel 4.15.x 4.19.2 - map_write() CAP_SYS_ADMIN Local Privilege Escalation (cron Method)
2018-11-21 bcolesEXPLOITPACKBash
Linux Kernel 4.15.x < 4.19.2 - 'map_write() CAP_SYS_ADMIN' Local Privilege Escalation (ldpreload Method)
2018-11-21 bcolesEXPLOITDBBash
Linux Kernel 4.15.x < 4.19.2 - 'map_write() CAP_SYS_ADMIN' Local Privilege Escalation (cron Method)
2018-11-21 bcolesEXPLOITDBBash
Linux - Broken uid/gid Mapping for Nested User Namespaces Exploit
2018-11-16 Google Security ResearchZDT
Linux - Broken uidgid Mapping for Nested User Namespaces
2018-11-16 Google Security ResearchEXPLOITPACK
Linux - Broken uid/gid Mapping for Nested User Namespaces
2018-11-16 Google Security ResearchEXPLOITDB
Linux Nested User Namespace idmap Limit Local Privilege Escalation
2018-11-15 Jann Horn, bcoles <bcoles@gmail.com>METASPLOITRuby