Linux Nested User Namespace idmap Limit Local Privilege Escalation
zetlyn/cve-metasploit exploit cve CVE-2018-18955 known 2018-11-15
Properties
| platform | Linuxreceipt
What the source handed over{
"actions": [],
"aliases": [],
"arch": "x86, x64",
"author": [
"Jann Horn",
"bcoles <bcoles@gmail.com>"
],
"autofilter_ports": [],
"autofilter_services": [],
"check": true,
"default_credential": false,
"description": "This module exploits a vulnerability in Linux kernels 4.15.0 to 4.18.18,\n and 4.19.0 to 4.19.1, where broken uid/gid mappings between nested user\n namespaces and kernel uid/gid mappings allow elevation to root\n (CVE-2018-18955).\n\n The target system must have unprivileged user namespaces enabled and\n the newuidmap and newgidmap helpers installed (from uidmap package).\n\n This module has been tested successfully on:\n\n Fedora Workstation 28 kernel 4.16.3-301.fc28.x86_64;\n Kubuntu 18.04 LTS kernel 4.15.0-20-generic (x86_64);\n Linux Mint 19 kernel 4.15.0-20-generic (x86_64);\n Ubuntu Linux 18.04.1 LTS kernel 4.15.0-20-generic (x86_64).",
"disclosure_date": "2018-11-15",
"fullname": "exploit/linux/local/nested_namespace_idmap_limit_priv_esc",
"is_install_path": true,
"mod_time": "2026-05-14 11:43:36 +0000",
"name": "Linux Nested User Namespace idmap Limit Local Privilege Escalation",
"needs_cleanup": true,
"notes": {
"AKA": [
"subuid_shell.c"
],
"Reliability": [
"repeatable-session"
],
"SideEffects": [
"unknown-side-effects"
],
"Stability": [
"crash-safe"
]
},
"path": "/modules/exploits/linux/local/nested_namespace_idmap_limit_priv_esc.rb",
"platform": "Linux",
"post_auth": false,
"rank": 500,
"ref_name": "linux/local/nested_namespace_idmap_limit_priv_esc",
"references": [
"BID-105941",
"CVE-2018-18955",
"EDB-45886",
"PACKETSTORM-150381",
"URL-https://bugs.chromium.org/p/project-zero/issues/detail?id=1712",
"URL-https://github.com/bcoles/kernel-exploits/tree/master/CVE-2018-18955",
"URL-https://lwn.net/Articles/532593/",
"URL-https://bugs.launchpad.net/bugs/1801924",
"URL-https://people.canonical.com/~ubuntu-security/cve/CVE-2018-18955",
"URL-https://security-tracker.debian.org/tracker/CVE-2018-18955",
"URL-https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=d2f007dbe7e4c9583eea6eb04d60001e85c6f1bd",
"URL-https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.18.19",
"URL-https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.2"
],
"rport": null,
"session_types": [
"shell",
"meterpreter"
],
"targets": [
"Auto"
],
"type": "exploit"
} |
|---|---|
| rank | 500 Great. Detects the target automatically, or uses an application-specific return address. receipt
What the source handed over{
"actions": [],
"aliases": [],
"arch": "x86, x64",
"author": [
"Jann Horn",
"bcoles <bcoles@gmail.com>"
],
"autofilter_ports": [],
"autofilter_services": [],
"check": true,
"default_credential": false,
"description": "This module exploits a vulnerability in Linux kernels 4.15.0 to 4.18.18,\n and 4.19.0 to 4.19.1, where broken uid/gid mappings between nested user\n namespaces and kernel uid/gid mappings allow elevation to root\n (CVE-2018-18955).\n\n The target system must have unprivileged user namespaces enabled and\n the newuidmap and newgidmap helpers installed (from uidmap package).\n\n This module has been tested successfully on:\n\n Fedora Workstation 28 kernel 4.16.3-301.fc28.x86_64;\n Kubuntu 18.04 LTS kernel 4.15.0-20-generic (x86_64);\n Linux Mint 19 kernel 4.15.0-20-generic (x86_64);\n Ubuntu Linux 18.04.1 LTS kernel 4.15.0-20-generic (x86_64).",
"disclosure_date": "2018-11-15",
"fullname": "exploit/linux/local/nested_namespace_idmap_limit_priv_esc",
"is_install_path": true,
"mod_time": "2026-05-14 11:43:36 +0000",
"name": "Linux Nested User Namespace idmap Limit Local Privilege Escalation",
"needs_cleanup": true,
"notes": {
"AKA": [
"subuid_shell.c"
],
"Reliability": [
"repeatable-session"
],
"SideEffects": [
"unknown-side-effects"
],
"Stability": [
"crash-safe"
]
},
"path": "/modules/exploits/linux/local/nested_namespace_idmap_limit_priv_esc.rb",
"platform": "Linux",
"post_auth": false,
"rank": 500,
"ref_name": "linux/local/nested_namespace_idmap_limit_priv_esc",
"references": [
"BID-105941",
"CVE-2018-18955",
"EDB-45886",
"PACKETSTORM-150381",
"URL-https://bugs.chromium.org/p/project-zero/issues/detail?id=1712",
"URL-https://github.com/bcoles/kernel-exploits/tree/master/CVE-2018-18955",
"URL-https://lwn.net/Articles/532593/",
"URL-https://bugs.launchpad.net/bugs/1801924",
"URL-https://people.canonical.com/~ubuntu-security/cve/CVE-2018-18955",
"URL-https://security-tracker.debian.org/tracker/CVE-2018-18955",
"URL-https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=d2f007dbe7e4c9583eea6eb04d60001e85c6f1bd",
"URL-https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.18.19",
"URL-https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.2"
],
"rport": null,
"session_types": [
"shell",
"meterpreter"
],
"targets": [
"Auto"
],
"type": "exploit"
} |
Text
This module exploits a vulnerability in Linux kernels 4.15.0 to 4.18.18,
and 4.19.0 to 4.19.1, where broken uid/gid mappings between nested user
namespaces and kernel uid/gid mappings allow elevation to root
(CVE-2018-18955).
The target system must have unprivileged user namespaces enabled and
the newuidmap and newgidmap helpers installed (from uidmap package).
This module has been tested successfully on:
Fedora Workstation 28 kernel 4.16.3-301.fc28.x86_64;
Kubuntu 18.04 LTS kernel 4.15.0-20-generic (x86_64);
Linux Mint 19 kernel 4.15.0-20-generic (x86_64);
Ubuntu Linux 18.04.1 LTS kernel 4.15.0-20-generic (x86_64).