7.8
CVSSv3

CVE-2018-13405

Published: 06/07/2018 Updated: 07/11/2023
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 465
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The inode_init_owner function in fs/inode.c in the Linux kernel up to and including 3.16 allows local users to create files with an unintended group ownership, in a scenario where a directory is SGID to a certain group and is writable by a user who is not a member of that group. Here, the non-member can trigger creation of a plain file whose group ownership is that group. The intended behavior was that the non-member can trigger creation of a directory (but not a plain file) whose group ownership is that group. The non-member can escalate privileges by making the plain file executable and SGID.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

linux linux kernel

debian debian linux 8.0

debian debian linux 9.0

canonical ubuntu linux 16.04

canonical ubuntu linux 14.04

canonical ubuntu linux 18.04

fedoraproject fedora 34

fedoraproject fedora 35

redhat enterprise linux desktop 7.0

redhat enterprise linux server aus 7.2

redhat enterprise linux workstation 7.0

redhat enterprise linux server tus 7.2

redhat enterprise linux server 7.0

redhat enterprise linux server aus 6.6

redhat enterprise linux for real time 7

redhat enterprise linux desktop 6.0

redhat enterprise linux server 6.0

redhat enterprise linux workstation 6.0

redhat enterprise linux server tus 7.3

redhat enterprise linux server aus 7.3

redhat virtualization 4.0

redhat enterprise linux server tus 7.4

redhat enterprise linux aus 7.4

redhat enterprise linux eus 7.4

redhat enterprise linux eus 7.5

redhat mrg realtime 2.0

f5 big-ip application acceleration manager 15.1.0

f5 big-ip local traffic manager 15.1.0

f5 big-ip advanced firewall manager 15.1.0

f5 big-ip policy enforcement manager 15.1.0

f5 big-ip link controller 15.1.0

f5 big-ip global traffic manager 15.1.0

f5 big-ip fraud protection service 15.1.0

f5 big-ip domain name system 15.1.0

f5 big-ip application security manager 15.1.0

f5 big-ip access policy manager 15.1.0

f5 big-ip analytics 15.1.0

f5 big-ip advanced firewall manager

f5 big-ip analytics

f5 big-ip application acceleration manager

f5 big-ip application security manager

f5 big-ip domain name system

f5 big-ip fraud protection service

f5 big-ip global traffic manager

f5 big-ip link controller

f5 big-ip local traffic manager

f5 big-ip policy enforcement manager

f5 big-ip access policy manager

f5 big-ip edge gateway

f5 big-ip webaccelerator

f5 big-ip access policy manager 16.0.0

f5 big-ip advanced firewall manager 16.0.0

f5 big-ip analytics 16.0.0

f5 big-ip application acceleration manager 16.0.0

f5 big-ip application security manager 16.0.0

f5 big-ip domain name system 16.0.0

f5 big-ip fraud protection service 16.0.0

f5 big-ip global traffic manager 16.0.0

f5 big-ip link controller 16.0.0

f5 big-ip local traffic manager 16.0.0

f5 big-ip policy enforcement manager 16.0.0

f5 big-ip webaccelerator 16.0.0

f5 big-ip webaccelerator 15.1.0

f5 big-ip edge gateway 16.0.0

f5 big-ip edge gateway 15.1.0

Vendor Advisories

Synopsis Important: kernel security and bug fix update Type/Severity Security Advisory: Important Topic An update for kernel is now available for Red Hat Enterprise Linux 6Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) b ...
Synopsis Important: kernel security, bug fix, and enhancement update Type/Severity Security Advisory: Important Topic An update for kernel is now available for Red Hat Enterprise Linux 75 Extended Update SupportRed Hat Product Security has rated this update as having a security impact of Important A Comm ...
Synopsis Important: kernel security, bug fix, and enhancement update Type/Severity Security Advisory: Important Topic An update for kernel is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring S ...
Synopsis Important: kernel security update Type/Severity Security Advisory: Important Topic An update for kernel is now available for Red Hat Enterprise Linux 66 Advanced Update SupportRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring S ...
Synopsis Important: kernel security and bug fix update Type/Severity Security Advisory: Important Topic An update for kernel is now available for Red Hat Enterprise Linux 72 Advanced Update Support, Red Hat Enterprise Linux 72 Telco Extended Update Support, and Red Hat Enterprise Linux 72 Update Services ...
Synopsis Important: kernel-rt security, bug fix, and enhancement update Type/Severity Security Advisory: Important Topic An update for kernel-rt is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Sco ...
Synopsis Important: kernel security and bug fix update Type/Severity Security Advisory: Important Topic An update for kernel is now available for Red Hat Enterprise Linux 74 Extended Update SupportRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerabili ...
Synopsis Important: kernel security and bug fix update Type/Severity Security Advisory: Important Topic An update for kernel is now available for Red Hat Enterprise Linux 73 Advanced Update Support, Red Hat Enterprise Linux 73 Telco Extended Update Support, and Red Hat Enterprise Linux 73 Update Services ...
Synopsis Important: kernel-rt security and bug fix update Type/Severity Security Advisory: Important Topic An update for kernel-rt is now available for Red Hat Enterprise MRG 2Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVS ...
Synopsis Important: kernel-alt security, bug fix, and enhancement update Type/Severity Security Advisory: Important Topic An update for kernel-alt is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability S ...
Several security issues were fixed in the Linux kernel ...
Several security issues were fixed in the Linux kernel ...
Several security issues were fixed in the Linux kernel ...
Several security issues were fixed in the Linux kernel ...
A vulnerability was found in the fs/inodec:inode_init_owner() function logic of the LInux kernel that allows local users to create files with an unintended group ownership and with group execution and SGID permission bits set, in a scenario where a directory is SGID and belongs to a certain group and is writable by a user who is not a member of th ...
A vulnerability was found in the fs/inodec:inode_init_owner() function logic of the LInux kernel that allows local users to create files with an unintended group ownership and with group execution and SGID permission bits set, in a scenario where a directory is SGID and belongs to a certain group and is writable by a user who is not a member of th ...

Exploits

/* Note: I am both sending this bug report to security@kernelorg and filing it in the Ubuntu bugtracker because I can't tell whether this counts as a kernel bug or as a Ubuntu bug You may wish to talk to each other to determine the best place to fix this I noticed halfdog's old writeup at wwwhalfdognet/Security/2015/SetgidDirectoryPri ...

Recent Articles

Facebook Messenger backdoor demand, bail in Bitcoin, and lots more
The Register • Shaun Nichols in San Francisco • 18 Aug 2018

If you're not already suffering from Black Hat/DEF CON overload They're back! 'Feds only' encryption backdoors prepped in US by Dems

Roundup It's time for another rapid roundup of computer security news beyond what we've already reported. Uncle Sam is demanding Facebook alter its Messenger software so that American g-men can easily snoop on suspected criminals, it is claimed. The social network is said to be fighting off demands by the US government to deliberately hobble the strong encryption in its chat software, and allow voice conversations to be spied on by investigators. Prosecutors are trying to hold Facebook in contem...

References

CWE-269https://twitter.com/grsecurity/status/1015082951204327425https://github.com/torvalds/linux/commit/0fa3ecd87848c9c93c2c828ef4c3a8ca36ce46c7http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=0fa3ecd87848c9c93c2c828ef4c3a8ca36ce46c7http://openwall.com/lists/oss-security/2018/07/13/2https://www.exploit-db.com/exploits/45033/https://www.debian.org/security/2018/dsa-4266https://lists.debian.org/debian-lts-announce/2018/08/msg00014.htmlhttps://usn.ubuntu.com/3754-1/https://usn.ubuntu.com/3753-2/https://usn.ubuntu.com/3753-1/https://usn.ubuntu.com/3752-2/https://usn.ubuntu.com/3752-1/https://usn.ubuntu.com/3752-3/https://access.redhat.com/errata/RHSA-2018:3096https://access.redhat.com/errata/RHSA-2018:3083https://access.redhat.com/errata/RHSA-2018:2948http://www.securityfocus.com/bid/106503https://access.redhat.com/errata/RHSA-2019:0717https://support.f5.com/csp/article/K00854051https://access.redhat.com/errata/RHSA-2019:2476https://access.redhat.com/errata/RHSA-2019:2566https://access.redhat.com/errata/RHSA-2019:2696https://access.redhat.com/errata/RHSA-2019:2730https://access.redhat.com/errata/RHSA-2019:4164https://access.redhat.com/errata/RHSA-2019:4159https://git.kernel.org/pub/scm/linux/kernel/git/tip/tip.git/commit/?id=0b3369840cd61c23e2b9241093737b4c395cb406https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MTKKIAUMR5FAYLZ7HLEPOXMKAAE3BYBQ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HRBNBX73SAFKQWBOX76SLMWPTKJPVGEJ/https://nvd.nist.govhttps://www.exploit-db.com/exploits/45033/https://usn.ubuntu.com/3753-2/https://www.cisa.gov/news-events/ics-advisories/icsa-24-046-11