CVE-2018-6559
published 2018-10-26CVE-2018-6559: The Linux kernel, as used in Ubuntu 18.04 LTS and Ubuntu 18.10, allows local users to obtain names of files in which they would not normally be able to access…
PriorityP410low3.3CVSS 3.0
AVLACLPRLUINSUCLINAN
EPSS
0.53%
42.0th percentile
The Linux kernel, as used in Ubuntu 18.04 LTS and Ubuntu 18.10, allows local users to obtain names of files in which they would not normally be able to access via an overlayfs mount inside of a user namespace.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | linux | — | — |
| linux | linux_kernel | >= 0 < 4.15.0-42.45 | 4.15.0-42.45 |
CVSS provenance
nvdv3.03.3LOWCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv7.0HIGH
vendor_ubuntu7.0HIGH
vendor_debian3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel (HWE) vulnerabilities
vendor_ubuntu·2018-12-04·CVSS 7.0
CVE-2018-18955 [HIGH] Linux kernel (HWE) vulnerabilities
Title: Linux kernel (HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-3836-1 fixed vulnerabilities in the Linux kernel for Ubuntu 18.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 18.04 LTS for Ubuntu
16.04 LTS.
Jann Horn discovered that the Linux kernel mishandles mapping UID or GID
ranges inside nested user namespaces in some situations. A local attacker
could use this to bypass access controls on resources outside the
namespace. (CVE-2018-18955)
Philipp Wendler discovered that the overlayfs implementation in the Linux
kernel did not properly verify the directory contents permissions from
within a unprivileged user namespace. A local attacker could use this to
expose sensitive
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2018-12-03·CVSS 5.5
CVE-2018-17972 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Jann Horn discovered that the procfs file system implementation in the
Linux kernel did not properly restrict the ability to inspect the kernel
stack of an arbitrary task. A local attacker could use this to expose
sensitive information. (CVE-2018-17972)
Jann Horn discovered that the mremap() system call in the Linux kernel did
not properly flush the TLB when completing, potentially leaving access to a
physical page after it has been released to the page allocator. A local
attacker could use this to cause a denial of service (system crash), expose
sensitive information, or possibly execute arbitrary code. (CVE-2018-18281)
It was discovered that the BPF verifier in the Linux kernel did no
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2018-12-03·CVSS 7.0
CVE-2018-18955 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Jann Horn discovered that the Linux kernel mishandles mapping UID or GID
ranges inside nested user namespaces in some situations. A local attacker
could use this to bypass access controls on resources outside the
namespace. (CVE-2018-18955)
Philipp Wendler discovered that the overlayfs implementation in the Linux
kernel did not properly verify the directory contents permissions from
within a unprivileged user namespace. A local attacker could use this to
expose sensitive information (protected file names). (CVE-2018-6559)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kerne
Ubuntu
Linux kernel (AWS) vulnerabilities
vendor_ubuntu·2018-11-30·CVSS 7.0
CVE-2018-18955 [HIGH] Linux kernel (AWS) vulnerabilities
Title: Linux kernel (AWS) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Jann Horn discovered that the Linux kernel mishandles mapping UID or GID
ranges inside nested user namespaces in some situations. A local attacker
could use this to bypass access controls on resources outside the
namespace. (CVE-2018-18955)
Philipp Wendler discovered that the overlayfs implementation in the Linux
kernel did not properly verify the directory contents permissions from
within a unprivileged user namespace. A local attacker could use this to
expose sensitive information (protected file names). (CVE-2018-6559)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the
Ubuntu
Linux kernel (AWS) vulnerabilities
vendor_ubuntu·2018-11-30·CVSS 5.5
CVE-2018-17972 [MEDIUM] Linux kernel (AWS) vulnerabilities
Title: Linux kernel (AWS) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Jann Horn discovered that the procfs file system implementation in the
Linux kernel did not properly restrict the ability to inspect the kernel
stack of an arbitrary task. A local attacker could use this to expose
sensitive information. (CVE-2018-17972)
Jann Horn discovered that the mremap() system call in the Linux kernel did
not properly flush the TLB when completing, potentially leaving access to a
physical page after it has been released to the page allocator. A local
attacker could use this to cause a denial of service (system crash), expose
sensitive information, or possibly execute arbitrary code. (CVE-2018-18281)
It was discovered that the BPF verifier in the Linux kernel
Debian
CVE-2018-6559: linux - The Linux kernel, as used in Ubuntu 18.04 LTS and Ubuntu 18.10, allows local use...
vendor_debian·2018·CVSS 3.3
CVE-2018-6559 [LOW] CVE-2018-6559: linux - The Linux kernel, as used in Ubuntu 18.04 LTS and Ubuntu 18.10, allows local use...
The Linux kernel, as used in Ubuntu 18.04 LTS and Ubuntu 18.10, allows local users to obtain names of files in which they would not normally be able to access via an overlayfs mount inside of a user namespace.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
GHSA-ff3j-qf4h-7gcp: The Linux kernel, as used in Ubuntu 18
ghsa_unreviewed·2022-05-13
CVE-2018-6559 [LOW] CWE-200 GHSA-ff3j-qf4h-7gcp: The Linux kernel, as used in Ubuntu 18
The Linux kernel, as used in Ubuntu 18.04 LTS and Ubuntu 18.10, allows local users to obtain names of files in which they would not normally be able to access via an overlayfs mount inside of a user namespace.
OSV
linux-hwe, linux-gcp vulnerabilities
osv·2018-12-04·CVSS 7.0
CVE-2018-18955 [HIGH] linux-hwe, linux-gcp vulnerabilities
linux-hwe, linux-gcp vulnerabilities
USN-3836-1 fixed vulnerabilities in the Linux kernel for Ubuntu 18.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 18.04 LTS for Ubuntu
16.04 LTS.
Jann Horn discovered that the Linux kernel mishandles mapping UID or GID
ranges inside nested user namespaces in some situations. A local attacker
could use this to bypass access controls on resources outside the
namespace. (CVE-2018-18955)
Philipp Wendler discovered that the overlayfs implementation in the Linux
kernel did not properly verify the directory contents permissions from
within a unprivileged user namespace. A local attacker could use this to
expose sensitive information (protected file names). (CVE-2018-6559)
OSV
linux, linux-gcp, linux-kvm, linux-raspi2 vulnerabilities
osv·2018-12-03·CVSS 7.0
CVE-2018-18955 [HIGH] linux, linux-gcp, linux-kvm, linux-raspi2 vulnerabilities
linux, linux-gcp, linux-kvm, linux-raspi2 vulnerabilities
Jann Horn discovered that the Linux kernel mishandles mapping UID or GID
ranges inside nested user namespaces in some situations. A local attacker
could use this to bypass access controls on resources outside the
namespace. (CVE-2018-18955)
Philipp Wendler discovered that the overlayfs implementation in the Linux
kernel did not properly verify the directory contents permissions from
within a unprivileged user namespace. A local attacker could use this to
expose sensitive information (protected file names). (CVE-2018-6559)
OSV
linux-aws vulnerabilities
osv·2018-11-30·CVSS 7.0
CVE-2018-18955 [HIGH] linux-aws vulnerabilities
linux-aws vulnerabilities
Jann Horn discovered that the Linux kernel mishandles mapping UID or GID
ranges inside nested user namespaces in some situations. A local attacker
could use this to bypass access controls on resources outside the
namespace. (CVE-2018-18955)
Philipp Wendler discovered that the overlayfs implementation in the Linux
kernel did not properly verify the directory contents permissions from
within a unprivileged user namespace. A local attacker could use this to
expose sensitive information (protected file names). (CVE-2018-6559)
OSV
CVE-2018-6559: The Linux kernel, as used in Ubuntu 18
osv·2018-10-18·CVSS 3.3
CVE-2018-6559 [LOW] CVE-2018-6559: The Linux kernel, as used in Ubuntu 18
The Linux kernel, as used in Ubuntu 18.04 LTS and Ubuntu 18.10, allows local users to obtain names of files in which they would not normally be able to access via an overlayfs mount inside of a user namespace.
No detection rules found.
No public exploits indexed.
http://www.securityfocus.com/bid/105752https://launchpad.net/bugs/1793458https://lists.ubuntu.com/archives/kernel-team/2018-October/096172.htmlhttps://people.canonical.com/~ubuntu-security/cve/2018/CVE-2018-6559.htmlhttps://usn.ubuntu.com/3832-1/https://usn.ubuntu.com/3833-1/https://usn.ubuntu.com/3835-1/https://usn.ubuntu.com/3836-1/https://usn.ubuntu.com/3836-2/http://www.securityfocus.com/bid/105752https://launchpad.net/bugs/1793458https://lists.ubuntu.com/archives/kernel-team/2018-October/096172.htmlhttps://people.canonical.com/~ubuntu-security/cve/2018/CVE-2018-6559.htmlhttps://usn.ubuntu.com/3832-1/https://usn.ubuntu.com/3833-1/https://usn.ubuntu.com/3835-1/https://usn.ubuntu.com/3836-1/https://usn.ubuntu.com/3836-2/
2018-10-26
Published