Description
The inode_init_owner function in fs/inode.c in the Linux kernel through 3.16 allows local users to create files with an unintended group ownership, in a scenario where a directory is SGID to a certain group and is writable by a user who is not a member of that group. Here, the non-member can trigger creation of a plain file whose group ownership is that group. The intended behavior was that the non-member can trigger creation of a directory (but not a plain file) whose group ownership is that group. The non-member can escalate privileges by making the plain file executable and SGID.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1466-1 | linux-4.9 security update |
Debian DSA |
DSA-4266-1 | linux security update |
EUVD |
EUVD-2018-5348 | The inode_init_owner function in fs/inode.c in the Linux kernel through 3.16 allows local users to create files with an unintended group ownership, in a scenario where a directory is SGID to a certain group and is writable by a user who is not a member of that group. Here, the non-member can trigger creation of a plain file whose group ownership is that group. The intended behavior was that the non-member can trigger creation of a directory (but not a plain file) whose group ownership is that group. The non-member can escalate privileges by making the plain file executable and SGID. |
Ubuntu USN |
USN-3752-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-3752-2 | Linux kernel (HWE) vulnerabilities |
Ubuntu USN |
USN-3752-3 | Linux kernel (Azure, GCP, OEM) vulnerabilities |
Ubuntu USN |
USN-3753-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-3753-2 | Linux kernel (Xenial HWE) vulnerabilities |
Ubuntu USN |
USN-3754-1 | Linux kernel vulnerabilities |
References
History
No history.
Subscriptions
Canonical
Subscribe
Ubuntu Linux
Subscribe
Debian
Subscribe
Debian Linux
Subscribe
F5
Subscribe
Big-ip Access Policy Manager
Subscribe
Big-ip Advanced Firewall Manager
Subscribe
Big-ip Analytics
Subscribe
Big-ip Application Acceleration Manager
Subscribe
Big-ip Application Security Manager
Subscribe
Big-ip Domain Name System
Subscribe
Big-ip Edge Gateway
Subscribe
Big-ip Fraud Protection Service
Subscribe
Big-ip Global Traffic Manager
Subscribe
Big-ip Link Controller
Subscribe
Big-ip Local Traffic Manager
Subscribe
Big-ip Policy Enforcement Manager
Subscribe
Big-ip Webaccelerator
Subscribe
Fedoraproject
Subscribe
Fedora
Subscribe
Linux
Subscribe
Linux Kernel
Subscribe
Redhat
Subscribe
Enterprise Linux
Subscribe
Enterprise Linux Aus
Subscribe
Enterprise Linux Desktop
Subscribe
Enterprise Linux Eus
Subscribe
Enterprise Linux For Real Time
Subscribe
Enterprise Linux Server
Subscribe
Enterprise Linux Server Aus
Subscribe
Enterprise Linux Server Tus
Subscribe
Enterprise Linux Workstation
Subscribe
Enterprise Mrg
Subscribe
Mrg Realtime
Subscribe
Rhel Aus
Subscribe
Rhel E4s
Subscribe
Rhel Eus
Subscribe
Rhel Extras Rt
Subscribe
Rhel Tus
Subscribe
Virtualization
Subscribe
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T09:00:35.380Z
Reserved: 2018-07-06T00:00:00.000Z
Link: CVE-2018-13405
No data.
Status : Modified
Published: 2018-07-06T14:29:01.223
Modified: 2024-11-21T03:47:02.490
Link: CVE-2018-13405
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD
Ubuntu USN