CVE-2018-6559 Information

Description

The Linux kernel as used in Ubuntu 18.04 LTS and Ubuntu 18.10 allows local users to obtain names of files in which they would not normally be able to access via an overlayfs mount inside of a user namespace.

CVSS Vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Reference

http://www.securityfocus.com/bid/105752 https://launchpad.net/bugs/1793458 https://lists.ubuntu.com/archives/kernel-team/2018-October/096172.html https://people.canonical.com/~ubuntu-security/cve/2018/CVE-2018-6559.html https://usn.ubuntu.com/3832-1/ https://usn.ubuntu.com/3833-1/ https://usn.ubuntu.com/3835-1/ https://usn.ubuntu.com/3836-1/ https://usn.ubuntu.com/3836-2/

Attack Complexity

LOW

Privileges Required

LOW

User Interaction Required

LOW

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

LOW

Availability Impact

NONE

Base Score

NONE

Base Severity

3.3

Share on: