UBUNTU-CVE-2018-13405
Dashboard / Vulnerabilities / UBUNTU-CVE-2018-13405
UBUNTU-CVE-2018-13405
Summary:
Details: The inode_init_owner function in fs/inode.c in the Linux kernel through 3.16 allows local users to create files with an unintended group ownership, in a scenario where a directory is SGID to a certain group and is writable by a user who is not a member of that group. Here, the non-member can trigger creation of a plain file whose group ownership is that group. The intended behavior was that the non-member can trigger creation of a directory (but not a plain file) whose group ownership is that group. The non-member can escalate privileges by making the plain file executable and SGID.
References: https://ubuntu.com/security/CVE-2018-13405, https://git.kernel.org/linux/0fa3ecd87848c9c93c2c828ef4c3a8ca36ce46c7, https://twitter.com/grsecurity/status/1015082951204327425, https://www.halfdog.net/Security/2015/SetgidDirectoryPrivilegeEscalation/, https://ubuntu.com/security/notices/USN-3752-1, https://ubuntu.com/security/notices/USN-3752-2, https://ubuntu.com/security/notices/USN-3753-1, https://ubuntu.com/security/notices/USN-3753-2, https://ubuntu.com/security/notices/USN-3754-1, https://ubuntu.com/security/notices/USN-3752-3, https://www.cve.org/CVERecord?id=CVE-2018-13405
Affected packages
Package
Name: linux
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
