CVE-2018-18955
In the Linux kernel 4.15.x through 4.19.x before 4.19.2, map_write() in kernel/user_namespace.c allows privilege escalation because it mishandles nested user namespaces with more than 5 UID or GID ranges. A user who has CAP_SYS_ADMIN in an affected user namespace can bypass access controls on resources outside the namespace, as demonstrated by reading /etc/shadow. This occurs because an ID transformation takes place properly for the namespaced-to-kernel direction but not for the kernel-to-namespaced direction.
- Affected products
- Alt Linux, Linux Kernel, Ubuntu
- Linux Linux Kernel
- < 4.19.2
- Fix
- Available
- CVSS 3.0
- 7.0 HIGH
- EPSS
- 7.6% (94th percentile)
- Weakness
- CWE-863
- NVD status
- Modified
- Published
- 2018-11-16
CVE-2018-18955 at NVD
27 known exploits for CVE-2018-18955
Proof-of-concept code and exploit modules indexed by Sploitus
CVE-2018-18955
linux-kernel-exploits
kernel-exploits
CVE-2018-18955
Exploit for Use After Free in Linux Linux_Kernel
Exploit for Incorrect Authorization in Linux Linux_Kernel
Exploit for Use After Free in Linux Linux_Kernel
Exploit for Use After Free in Linux Linux_Kernel
Linux Kernel 4.15.x < 4.19.2 - map_write() CAP_SYS_ADMIN Local Privilege Escalation Exploit
Linux Kernel 4.15.x < 4.19.2 - map_write() CAP_SYS_ADMIN Local Privilege Escalation (cron Method)
Linux Kernel 4.15.x < 4.19.2 - map_write() CAP_SYS_ADMIN Local Privilege Escalation (polkit)
Linux Kernel 4.15.x < 4.19.2 - map_write() CAP_SYS_ADMIN Local Privilege Escalation (ldpreload)
Linux Kernel 4.15.x 4.19.2 - map_write() CAP_SYS_ADMIN Local Privilege Escalation (dbus Method)
Linux Kernel 4.15.x 4.19.2 - map_write() CAP_SYS_ADMIN Local Privilege Escalation (polkit Method)
Linux Kernel 4.15.x < 4.19.2 - 'map_write() CAP_SYS_ADMIN' Local Privilege Escalation (polkit Method)
Linux Kernel 4.15.x < 4.19.2 - 'map_write() CAP_SYS_ADMIN' Local Privilege Escalation (dbus Method)
Linux - Nested User Namespace idmap Limit Local Privilege Escalation (Metasploit)
Linux Nested User Namespace idmap Limit Local Privilege Escalation Exploit
Linux Nested User Namespace idmap Limit Local Privilege Escalation
Linux Kernel 4.15.x 4.19.2 - map_write() CAP_SYS_ADMIN Local Privilege Escalation (ldpreload Method)
Linux Kernel 4.15.x 4.19.2 - map_write() CAP_SYS_ADMIN Local Privilege Escalation (cron Method)
Linux Kernel 4.15.x < 4.19.2 - 'map_write() CAP_SYS_ADMIN' Local Privilege Escalation (ldpreload Method)
Linux Kernel 4.15.x < 4.19.2 - 'map_write() CAP_SYS_ADMIN' Local Privilege Escalation (cron Method)
Linux - Broken uid/gid Mapping for Nested User Namespaces Exploit
Linux - Broken uidgid Mapping for Nested User Namespaces
Linux - Broken uid/gid Mapping for Nested User Namespaces
Linux Nested User Namespace idmap Limit Local Privilege Escalation