CVE-2018-18955 is a local privilege escalation vulnerability in Linux kernel versions 4.15.x through 4.19.1, affecting Canonical and Linux distributions. It arises from improper handling of nested user namespaces with more than five UID or GID ranges, allowing a user with CAP_SYS_ADMIN in an affected namespace to bypass access controls and read sensitive files like /etc/shadow. With a CVSS score of 7.0 (HIGH), this vulnerability has a low attack complexity and requires local access, but can lead to full compromise of confidentiality, integrity, and availability. While not currently on the KEV catalog, multiple public exploits exist, including Metasploit modules and several ExploitDB entries, indicating readily available attack vectors. Despite the availability of exploit code, there is minimal community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.15, < 4.19.2CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
16.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:* | ||
18.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:* | ||
18.10CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:18.10:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.4 InfoSec Media, 0.1 Vendor Blog, and 0.0 Security Researcher mentions.