Linux Nested User Namespace idmap Limit Local Privilege Escalation

cve CVE-2018-18955 2 sources, 7 claims · Watch

Metasploit exploit modules writes:
This module exploits a vulnerability in Linux kernels 4.15.0 to 4.18.18, and 4.19.0 to 4.19.1, where broken uid/gid mappings between nested user namespaces and kernel uid/gid mappings allow elevation to root (CVE-2018-18955). The target system must have unprivileged user namespaces enabled and the newuidmap and newgidmap helpers installed (from uidmap package). This module has been tested successfully on: Fedora Workstation 28 kernel 4.16.3-301.fc28.x86_64; Kubuntu 18.04 LTS kernel 4.15.0-20-generic (x86_64); … the claim

What each source says

PropertySourceSaidMeans here
Author
author
Exploit-DBGoogle Security Research
receipt
Source
Exploit-DB
Its words
Google Security Research
Read by
field:author
Said since
2026-09-29 09:40 UTC
Last answered
2026-10-02 12:02 UTC
Original
open at the source
What the source handed over
{
  "aliases": "",
  "application_url": "",
  "author": "Google Security Research",
  "codes": "CVE-2018-18955",
  "date_added": "2018-11-16",
  "date_published": "2018-11-16",
  "date_updated": "2018-11-16",
  "description": "Linux - Broken uid/gid Mapping for Nested User Namespaces",
  "file": "exploits/linux/local/45886.txt",
  "id": "45886",
  "platform": "linux",
  "port": "",
  "screenshot_url": "",
  "source_url": "https://bugs.chromium.org/p/project-zero/issues/detail?id=1712",
  "tags": "Local",
  "type": "local",
  "verified": "1"
}
—
Author
author
Metasploit
receipt
Source
Exploit-DB
Its words
Metasploit
Read by
field:author
Said since
2026-09-29 09:40 UTC
Last answered
2026-10-02 12:02 UTC
Original
open at the source
What the source handed over
{
  "aliases": "",
  "application_url": "",
  "author": "Metasploit",
  "codes": "CVE-2018-18955",
  "date_added": "2018-11-29",
  "date_published": "2018-11-29",
  "date_updated": "2018-11-29",
  "description": "Linux - Nested User Namespace idmap Limit Local Privilege Escalation (Metasploit)",
  "file": "exploits/linux/local/45915.rb",
  "id": "45915",
  "platform": "linux",
  "port": "",
  "screenshot_url": "",
  "source_url": "https://raw.githubusercontent.com/rapid7/metasploit-framework/66cae6240f3f24d2fc84223c71c1653da4d22152/modules/exploits/linux/local/nested_namespace_idmap_limit_priv_esc.rb",
  "tags": "Metasploit Framework (MSF)",
  "type": "local",
  "verified": "1"
}
—
Author
author
bcoles
receipt
Source
Exploit-DB
Its words
bcoles
Read by
field:author
Said since
2026-09-29 09:40 UTC
Last answered
2026-10-02 12:02 UTC
Original
open at the source
What the source handed over
{
  "aliases": "",
  "application_url": "",
  "author": "bcoles",
  "codes": "CVE-2018-18955",
  "date_added": "2019-07-26",
  "date_published": "2018-11-21",
  "date_updated": "2019-07-26",
  "description": "Linux Kernel 4.15.x < 4.19.2 - 'map_write() CAP_SYS_ADMIN' Local Privilege Escalation (cron Method)",
  "file": "exploits/linux/local/47164.sh",
  "id": "47164",
  "platform": "linux",
  "port": "",
  "screenshot_url": "",
  "source_url": "https://github.com/bcoles/kernel-exploits/blob/4be5baae0135c9370420a21134f980b21a5ac1ab/CVE-2018-18955/exploit.cron.sh",
  "tags": "",
  "type": "local",
  "verified": "0"
}
—
Platform
platform
not compared
Exploit-DBlinux
receipt
Source
Exploit-DB
Its words
linux
Read by
field:platform
Said since
2026-09-29 09:40 UTC
Last answered
2026-10-02 12:02 UTC
Original
open at the source
What the source handed over
{
  "aliases": "",
  "application_url": "",
  "author": "Google Security Research",
  "codes": "CVE-2018-18955",
  "date_added": "2018-11-16",
  "date_published": "2018-11-16",
  "date_updated": "2018-11-16",
  "description": "Linux - Broken uid/gid Mapping for Nested User Namespaces",
  "file": "exploits/linux/local/45886.txt",
  "id": "45886",
  "platform": "linux",
  "port": "",
  "screenshot_url": "",
  "source_url": "https://bugs.chromium.org/p/project-zero/issues/detail?id=1712",
  "tags": "Local",
  "type": "local",
  "verified": "1"
}
—
Platform
platform
not compared
Metasploit exploit modulesLinux
receipt
Source
Metasploit exploit modules
Its words
Linux
Read by
field:platform
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 21:59 UTC
Original
open at the source
What the source handed over
{
  "actions": [],
  "aliases": [],
  "arch": "x86, x64",
  "author": [
    "Jann Horn",
    "bcoles <bcoles@gmail.com>"
  ],
  "autofilter_ports": [],
  "autofilter_services": [],
  "check": true,
  "default_credential": false,
  "description": "This module exploits a vulnerability in Linux kernels 4.15.0 to 4.18.18,\n          and 4.19.0 to 4.19.1, where broken uid/gid mappings between nested user\n          namespaces and kernel uid/gid mappings allow elevation to root\n          (CVE-2018-18955).\n\n          The target system must have unprivileged user namespaces enabled and\n          the newuidmap and newgidmap helpers installed (from uidmap package).\n\n          This module has been tested successfully on:\n\n          Fedora Workstation 28 kernel 4.16.3-301.fc28.x86_64;\n          Kubuntu 18.04 LTS kernel 4.15.0-20-generic (x86_64);\n          Linux Mint 19 kernel 4.15.0-20-generic (x86_64);\n          Ubuntu Linux 18.04.1 LTS kernel 4.15.0-20-generic (x86_64).",
  "disclosure_date": "2018-11-15",
  "fullname": "exploit/linux/local/nested_namespace_idmap_limit_priv_esc",
  "is_install_path": true,
  "mod_time": "2026-05-14 11:43:36 +0000",
  "name": "Linux Nested User Namespace idmap Limit Local Privilege Escalation",
  "needs_cleanup": true,
  "notes": {
    "AKA": [
      "subuid_shell.c"
    ],
    "Reliability": [
      "repeatable-session"
    ],
    "SideEffects": [
      "unknown-side-effects"
    ],
    "Stability": [
      "crash-safe"
    ]
  },
  "path": "/modules/exploits/linux/local/nested_namespace_idmap_limit_priv_esc.rb",
  "platform": "Linux",
  "post_auth": false,
  "rank": 500,
  "ref_name": "linux/local/nested_namespace_idmap_limit_priv_esc",
  "references": [
    "BID-105941",
    "CVE-2018-18955",
    "EDB-45886",
    "PACKETSTORM-150381",
    "URL-https://bugs.chromium.org/p/project-zero/issues/detail?id=1712",
    "URL-https://github.com/bcoles/kernel-exploits/tree/master/CVE-2018-18955",
    "URL-https://lwn.net/Articles/532593/",
    "URL-https://bugs.launchpad.net/bugs/1801924",
    "URL-https://people.canonical.com/~ubuntu-security/cve/CVE-2018-18955",
    "URL-https://security-tracker.debian.org/tracker/CVE-2018-18955",
    "URL-https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=d2f007dbe7e4c9583eea6eb04d60001e85c6f1bd",
    "URL-https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.18.19",
    "URL-https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.2"
  ],
  "rport": null,
  "session_types": [
    "shell",
    "meterpreter"
  ],
  "targets": [
    "Auto"
  ],
  "type": "exploit"
}
—
Rank
rank
Metasploit exploit modules500
Great. Detects the target automatically, or uses an application-specific return address.
receipt
Source
Metasploit exploit modules
Its words
500
Read by
field:rank
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 21:59 UTC
Original
open at the source
What the source handed over
{
  "actions": [],
  "aliases": [],
  "arch": "x86, x64",
  "author": [
    "Jann Horn",
    "bcoles <bcoles@gmail.com>"
  ],
  "autofilter_ports": [],
  "autofilter_services": [],
  "check": true,
  "default_credential": false,
  "description": "This module exploits a vulnerability in Linux kernels 4.15.0 to 4.18.18,\n          and 4.19.0 to 4.19.1, where broken uid/gid mappings between nested user\n          namespaces and kernel uid/gid mappings allow elevation to root\n          (CVE-2018-18955).\n\n          The target system must have unprivileged user namespaces enabled and\n          the newuidmap and newgidmap helpers installed (from uidmap package).\n\n          This module has been tested successfully on:\n\n          Fedora Workstation 28 kernel 4.16.3-301.fc28.x86_64;\n          Kubuntu 18.04 LTS kernel 4.15.0-20-generic (x86_64);\n          Linux Mint 19 kernel 4.15.0-20-generic (x86_64);\n          Ubuntu Linux 18.04.1 LTS kernel 4.15.0-20-generic (x86_64).",
  "disclosure_date": "2018-11-15",
  "fullname": "exploit/linux/local/nested_namespace_idmap_limit_priv_esc",
  "is_install_path": true,
  "mod_time": "2026-05-14 11:43:36 +0000",
  "name": "Linux Nested User Namespace idmap Limit Local Privilege Escalation",
  "needs_cleanup": true,
  "notes": {
    "AKA": [
      "subuid_shell.c"
    ],
    "Reliability": [
      "repeatable-session"
    ],
    "SideEffects": [
      "unknown-side-effects"
    ],
    "Stability": [
      "crash-safe"
    ]
  },
  "path": "/modules/exploits/linux/local/nested_namespace_idmap_limit_priv_esc.rb",
  "platform": "Linux",
  "post_auth": false,
  "rank": 500,
  "ref_name": "linux/local/nested_namespace_idmap_limit_priv_esc",
  "references": [
    "BID-105941",
    "CVE-2018-18955",
    "EDB-45886",
    "PACKETSTORM-150381",
    "URL-https://bugs.chromium.org/p/project-zero/issues/detail?id=1712",
    "URL-https://github.com/bcoles/kernel-exploits/tree/master/CVE-2018-18955",
    "URL-https://lwn.net/Articles/532593/",
    "URL-https://bugs.launchpad.net/bugs/1801924",
    "URL-https://people.canonical.com/~ubuntu-security/cve/CVE-2018-18955",
    "URL-https://security-tracker.debian.org/tracker/CVE-2018-18955",
    "URL-https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=d2f007dbe7e4c9583eea6eb04d60001e85c6f1bd",
    "URL-https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.18.19",
    "URL-https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.2"
  ],
  "rport": null,
  "session_types": [
    "shell",
    "meterpreter"
  ],
  "targets": [
    "Auto"
  ],
  "type": "exploit"
}
—
Type
type
Exploit-DBlocal
receipt
Source
Exploit-DB
Its words
local
Read by
field:type
Said since
2026-09-29 09:40 UTC
Last answered
2026-10-02 12:02 UTC
Original
open at the source
What the source handed over
{
  "aliases": "",
  "application_url": "",
  "author": "Google Security Research",
  "codes": "CVE-2018-18955",
  "date_added": "2018-11-16",
  "date_published": "2018-11-16",
  "date_updated": "2018-11-16",
  "description": "Linux - Broken uid/gid Mapping for Nested User Namespaces",
  "file": "exploits/linux/local/45886.txt",
  "id": "45886",
  "platform": "linux",
  "port": "",
  "screenshot_url": "",
  "source_url": "https://bugs.chromium.org/p/project-zero/issues/detail?id=1712",
  "tags": "Local",
  "type": "local",
  "verified": "1"
}
—
Verified
verified
Exploit-DBfalse
receipt
Source
Exploit-DB
Its words
0
Read by
field:verified
Said since
2026-09-29 09:40 UTC
Last answered
2026-10-02 12:02 UTC
Original
open at the source
What the source handed over
{
  "aliases": "",
  "application_url": "",
  "author": "bcoles",
  "codes": "CVE-2018-18955",
  "date_added": "2019-07-26",
  "date_published": "2018-11-21",
  "date_updated": "2019-07-26",
  "description": "Linux Kernel 4.15.x < 4.19.2 - 'map_write() CAP_SYS_ADMIN' Local Privilege Escalation (cron Method)",
  "file": "exploits/linux/local/47164.sh",
  "id": "47164",
  "platform": "linux",
  "port": "",
  "screenshot_url": "",
  "source_url": "https://github.com/bcoles/kernel-exploits/blob/4be5baae0135c9370420a21134f980b21a5ac1ab/CVE-2018-18955/exploit.cron.sh",
  "tags": "",
  "type": "local",
  "verified": "0"
}
—
Verified
verified
true
receipt
Source
Exploit-DB
Its words
1
Read by
field:verified
Said since
2026-09-29 09:40 UTC
Last answered
2026-10-02 12:02 UTC
Original
open at the source
What the source handed over
{
  "aliases": "",
  "application_url": "",
  "author": "Google Security Research",
  "codes": "CVE-2018-18955",
  "date_added": "2018-11-16",
  "date_published": "2018-11-16",
  "date_updated": "2018-11-16",
  "description": "Linux - Broken uid/gid Mapping for Nested User Namespaces",
  "file": "exploits/linux/local/45886.txt",
  "id": "45886",
  "platform": "linux",
  "port": "",
  "screenshot_url": "",
  "source_url": "https://bugs.chromium.org/p/project-zero/issues/detail?id=1712",
  "tags": "Local",
  "type": "local",
  "verified": "1"
}
—

exploit

Linux Nested User Namespace idmap Limit Local Privilege Escalation
zetlyn/cve-metasploit · 2018-11-15
platform Linux rank 500 source
Linux - Broken uid/gid Mapping for Nested User Namespaces
zetlyn/cve-exploitdb · 2018-11-16
author Google Security Research platform linux type local verified true source
Linux - Nested User Namespace idmap Limit Local Privilege Escalation (Metasploit)
zetlyn/cve-exploitdb · 2018-11-29
author Metasploit platform linux type local verified true source
Linux Kernel 4.15.x < 4.19.2 - 'map_write() CAP_SYS_ADMIN' Local Privilege Escalation (cron Method)
zetlyn/cve-exploitdb · 2018-11-21
author bcoles platform linux type local verified false source
Linux Kernel 4.15.x < 4.19.2 - 'map_write() CAP_SYS_ADMIN' Local Privilege Escalation (dbus Method)
zetlyn/cve-exploitdb · 2019-01-04
author bcoles platform linux type local verified false source
Linux Kernel 4.15.x < 4.19.2 - 'map_write() CAP_SYS_ADMIN' Local Privilege Escalation (ldpreload Method)
zetlyn/cve-exploitdb · 2018-11-21
author bcoles platform linux type local verified false source
Linux Kernel 4.15.x < 4.19.2 - 'map_write() CAP_SYS_ADMIN' Local Privilege Escalation (polkit Method)
zetlyn/cve-exploitdb · 2019-01-04
author bcoles platform linux type local verified false source