CVE-2018-13405 Details
Description
The inode_init_owner function in fs/inode.c in the Linux kernel through 3.16 allows local users to create files with an unintended group ownership, in a scenario where a directory is SGID to a certain group and is writable by a user who is not a member of that group. Here, the non-member can trigger creation of a plain file whose group ownership is that group. The intended behavior was that the non-member can trigger creation of a directory (but not a plain file) whose group ownership is that group. The non-member can escalate privileges by making the plain file executable and SGID.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-269 | Improper Privilege Management | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | <= 3.16 |
CPE
Remediation
| |
| debian debian linux | 8.0 9.0 |
CPE
Remediation
| |
| canonical ubuntu linux | 14.04 16.04 18.04 |
CPE
Remediation
| |
| fedoraproject fedora | 34 35 |
CPE
Remediation
| |
| redhat mrg realtime | 2.0 |
CPE
Remediation
| |
| redhat virtualization | 4.0 |
CPE
Remediation
| |
| redhat enterprise linux aus | 7.4 |
CPE
Remediation
| |
| redhat enterprise linux desktop | 6.0 7.0 |
CPE
Remediation
| |
| redhat enterprise linux eus | 7.4 7.5 |
CPE
Remediation
| |
| redhat enterprise linux for real time | 7 |
CPE
Remediation
| |
| redhat enterprise linux server | 6.0 7.0 |
CPE
Remediation
| |
| redhat enterprise linux server aus | 6.6 7.2 7.3 |
CPE
Remediation
| |
| redhat enterprise linux server tus | 7.2 7.3 7.4 |
CPE
Remediation
| |
| redhat enterprise linux workstation | 6.0 7.0 |
CPE
Remediation
| |
| f5 big-ip access policy manager | >= 13.0.0, < 13.1.3.5 >= 14.0.0, < 14.1.3.1 >= 15.0.0, < 15.0.1.4 15.1.0 16.0.0 |
CPE
Remediation
| |
| f5 big-ip advanced firewall manager | >= 13.0.0, < 13.1.3.5 >= 14.0.0, < 14.1.3.1 >= 15.0.0, < 15.0.1.4 15.1.0 16.0.0 |
CPE
Remediation
| |
| f5 big-ip analytics | >= 13.0.0, < 13.1.3.5 >= 14.0.0, < 14.1.3.1 >= 15.0.0, < 15.0.1.4 15.1.0 16.0.0 |
CPE
Remediation
| |
| f5 big-ip application acceleration manager | >= 13.0.0, < 13.1.3.5 >= 14.0.0, < 14.1.3.1 >= 15.0.0, < 15.0.1.4 15.1.0 16.0.0 |
CPE
Remediation
| |
| f5 big-ip application security manager | >= 13.0.0, < 13.1.3.5 >= 14.0.0, < 14.1.3.1 >= 15.0.0, < 15.0.1.4 15.1.0 16.0.0 |
CPE
Remediation
| |
| f5 big-ip domain name system | >= 13.0.0, < 13.1.3.5 >= 14.0.0, < 14.1.3.1 >= 15.0.0, < 15.0.1.4 15.1.0 16.0.0 |
CPE
Remediation
| |
| f5 big-ip edge gateway | >= 13.0.0, < 13.1.3.5 >= 14.0.0, < 14.1.3.1 >= 15.0.0, < 15.0.1.4 15.1.0 16.0.0 |
CPE
Remediation
| |
| f5 big-ip fraud protection service | >= 13.0.0, < 13.1.3.5 >= 14.0.0, < 14.1.3.1 >= 15.0.0, < 15.0.1.4 15.1.0 16.0.0 |
CPE
Remediation
| |
| f5 big-ip global traffic manager | >= 13.0.0, < 13.1.3.5 >= 14.0.0, < 14.1.3.1 >= 15.0.0, < 15.0.1.4 15.1.0 16.0.0 |
CPE
Remediation
| |
| f5 big-ip link controller | >= 13.0.0, < 13.1.3.5 >= 14.0.0, < 14.1.3.1 >= 15.0.0, < 15.0.1.4 15.1.0 16.0.0 |
CPE
Remediation
| |
| f5 big-ip local traffic manager | >= 13.0.0, < 13.1.3.5 >= 14.0.0, < 14.1.3.1 >= 15.0.0, < 15.0.1.4 15.1.0 16.0.0 |
CPE
Remediation
| |
| f5 big-ip policy enforcement manager | >= 13.0.0, < 13.1.3.5 >= 14.0.0, < 14.1.3.1 >= 15.0.0, < 15.0.1.4 15.1.0 16.0.0 |
CPE
Remediation
| |
| f5 big-ip webaccelerator | >= 13.0.0, < 13.1.3.5 >= 14.0.0, < 14.1.3.1 >= 15.0.0, < 15.0.1.4 15.1.0 16.0.0 |
CPE
Remediation
| |
Change History
25 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Nov 7, 2023 | CVE Modified | [email protected] |
| Apr 6, 2022 | Modified Analysis | [email protected] |
| Feb 25, 2022 | CVE Modified | [email protected] |
| Feb 15, 2022 | CVE Modified | [email protected] |
| Jan 5, 2021 | CVE Modified | [email protected] |
| Dec 10, 2019 | CVE Modified | [email protected] |
| Oct 3, 2019 | CWE Remap | [email protected] |
| Sep 11, 2019 | CVE Modified | [email protected] |
| Sep 10, 2019 | CVE Modified | [email protected] |
| Aug 27, 2019 | CVE Modified | [email protected] |
| Aug 13, 2019 | CVE Modified | [email protected] |
| May 9, 2019 | CVE Modified | [email protected] |
| Apr 9, 2019 | CVE Modified | [email protected] |
| Jan 10, 2019 | CVE Modified | [email protected] |
| Oct 31, 2018 | CVE Modified | [email protected] |
| Aug 29, 2018 | CVE Modified | [email protected] |
| Aug 28, 2018 | Initial Analysis | [email protected] |
| Aug 24, 2018 | CVE Modified | [email protected] |
| Aug 16, 2018 | CVE Modified | [email protected] |
| Aug 8, 2018 | CVE Modified | [email protected] |
| Jul 28, 2018 | CVE Modified | [email protected] |
| Jul 17, 2018 | CVE Modified | [email protected] |