Linux Nested User Namespace idmap Limit Local Privilege Escalation
cve CVE-2018-18955 2 sources, 7 claims · Watch
Metasploit exploit modules writes:
This module exploits a vulnerability in Linux kernels 4.15.0 to 4.18.18, and 4.19.0 to 4.19.1, where broken uid/gid mappings between nested user namespaces and kernel uid/gid mappings allow elevation to root (CVE-2018-18955). The target system must have unprivileged user namespaces enabled and the newuidmap and newgidmap helpers installed (from uidmap package). This module has been tested successfully on: Fedora Workstation 28 kernel 4.16.3-301.fc28.x86_64; Kubuntu 18.04 LTS kernel 4.15.0-20-generic (x86_64); … the claim
This module exploits a vulnerability in Linux kernels 4.15.0 to 4.18.18, and 4.19.0 to 4.19.1, where broken uid/gid mappings between nested user namespaces and kernel uid/gid mappings allow elevation to root (CVE-2018-18955). The target system must have unprivileged user namespaces enabled and the newuidmap and newgidmap helpers installed (from uidmap package). This module has been tested successfully on: Fedora Workstation 28 kernel 4.16.3-301.fc28.x86_64; Kubuntu 18.04 LTS kernel 4.15.0-20-generic (x86_64); … the claim
What each source says
| Property | Source | Said | Means here |
|---|---|---|---|
| Author author | Exploit-DB | Google Security Researchreceipt
What the source handed over{
"aliases": "",
"application_url": "",
"author": "Google Security Research",
"codes": "CVE-2018-18955",
"date_added": "2018-11-16",
"date_published": "2018-11-16",
"date_updated": "2018-11-16",
"description": "Linux - Broken uid/gid Mapping for Nested User Namespaces",
"file": "exploits/linux/local/45886.txt",
"id": "45886",
"platform": "linux",
"port": "",
"screenshot_url": "",
"source_url": "https://bugs.chromium.org/p/project-zero/issues/detail?id=1712",
"tags": "Local",
"type": "local",
"verified": "1"
} | — |
| Author author | Metasploitreceipt
What the source handed over{
"aliases": "",
"application_url": "",
"author": "Metasploit",
"codes": "CVE-2018-18955",
"date_added": "2018-11-29",
"date_published": "2018-11-29",
"date_updated": "2018-11-29",
"description": "Linux - Nested User Namespace idmap Limit Local Privilege Escalation (Metasploit)",
"file": "exploits/linux/local/45915.rb",
"id": "45915",
"platform": "linux",
"port": "",
"screenshot_url": "",
"source_url": "https://raw.githubusercontent.com/rapid7/metasploit-framework/66cae6240f3f24d2fc84223c71c1653da4d22152/modules/exploits/linux/local/nested_namespace_idmap_limit_priv_esc.rb",
"tags": "Metasploit Framework (MSF)",
"type": "local",
"verified": "1"
} | — | |
| Author author | bcolesreceipt
What the source handed over{
"aliases": "",
"application_url": "",
"author": "bcoles",
"codes": "CVE-2018-18955",
"date_added": "2019-07-26",
"date_published": "2018-11-21",
"date_updated": "2019-07-26",
"description": "Linux Kernel 4.15.x < 4.19.2 - 'map_write() CAP_SYS_ADMIN' Local Privilege Escalation (cron Method)",
"file": "exploits/linux/local/47164.sh",
"id": "47164",
"platform": "linux",
"port": "",
"screenshot_url": "",
"source_url": "https://github.com/bcoles/kernel-exploits/blob/4be5baae0135c9370420a21134f980b21a5ac1ab/CVE-2018-18955/exploit.cron.sh",
"tags": "",
"type": "local",
"verified": "0"
} | — | |
| Platform platform not compared | Exploit-DB | linuxreceipt
What the source handed over{
"aliases": "",
"application_url": "",
"author": "Google Security Research",
"codes": "CVE-2018-18955",
"date_added": "2018-11-16",
"date_published": "2018-11-16",
"date_updated": "2018-11-16",
"description": "Linux - Broken uid/gid Mapping for Nested User Namespaces",
"file": "exploits/linux/local/45886.txt",
"id": "45886",
"platform": "linux",
"port": "",
"screenshot_url": "",
"source_url": "https://bugs.chromium.org/p/project-zero/issues/detail?id=1712",
"tags": "Local",
"type": "local",
"verified": "1"
} | — |
| Platform platform not compared | Metasploit exploit modules | Linuxreceipt
What the source handed over{
"actions": [],
"aliases": [],
"arch": "x86, x64",
"author": [
"Jann Horn",
"bcoles <bcoles@gmail.com>"
],
"autofilter_ports": [],
"autofilter_services": [],
"check": true,
"default_credential": false,
"description": "This module exploits a vulnerability in Linux kernels 4.15.0 to 4.18.18,\n and 4.19.0 to 4.19.1, where broken uid/gid mappings between nested user\n namespaces and kernel uid/gid mappings allow elevation to root\n (CVE-2018-18955).\n\n The target system must have unprivileged user namespaces enabled and\n the newuidmap and newgidmap helpers installed (from uidmap package).\n\n This module has been tested successfully on:\n\n Fedora Workstation 28 kernel 4.16.3-301.fc28.x86_64;\n Kubuntu 18.04 LTS kernel 4.15.0-20-generic (x86_64);\n Linux Mint 19 kernel 4.15.0-20-generic (x86_64);\n Ubuntu Linux 18.04.1 LTS kernel 4.15.0-20-generic (x86_64).",
"disclosure_date": "2018-11-15",
"fullname": "exploit/linux/local/nested_namespace_idmap_limit_priv_esc",
"is_install_path": true,
"mod_time": "2026-05-14 11:43:36 +0000",
"name": "Linux Nested User Namespace idmap Limit Local Privilege Escalation",
"needs_cleanup": true,
"notes": {
"AKA": [
"subuid_shell.c"
],
"Reliability": [
"repeatable-session"
],
"SideEffects": [
"unknown-side-effects"
],
"Stability": [
"crash-safe"
]
},
"path": "/modules/exploits/linux/local/nested_namespace_idmap_limit_priv_esc.rb",
"platform": "Linux",
"post_auth": false,
"rank": 500,
"ref_name": "linux/local/nested_namespace_idmap_limit_priv_esc",
"references": [
"BID-105941",
"CVE-2018-18955",
"EDB-45886",
"PACKETSTORM-150381",
"URL-https://bugs.chromium.org/p/project-zero/issues/detail?id=1712",
"URL-https://github.com/bcoles/kernel-exploits/tree/master/CVE-2018-18955",
"URL-https://lwn.net/Articles/532593/",
"URL-https://bugs.launchpad.net/bugs/1801924",
"URL-https://people.canonical.com/~ubuntu-security/cve/CVE-2018-18955",
"URL-https://security-tracker.debian.org/tracker/CVE-2018-18955",
"URL-https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=d2f007dbe7e4c9583eea6eb04d60001e85c6f1bd",
"URL-https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.18.19",
"URL-https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.2"
],
"rport": null,
"session_types": [
"shell",
"meterpreter"
],
"targets": [
"Auto"
],
"type": "exploit"
} | — |
| Rank rank | Metasploit exploit modules | 500 Great. Detects the target automatically, or uses an application-specific return address. receipt
What the source handed over{
"actions": [],
"aliases": [],
"arch": "x86, x64",
"author": [
"Jann Horn",
"bcoles <bcoles@gmail.com>"
],
"autofilter_ports": [],
"autofilter_services": [],
"check": true,
"default_credential": false,
"description": "This module exploits a vulnerability in Linux kernels 4.15.0 to 4.18.18,\n and 4.19.0 to 4.19.1, where broken uid/gid mappings between nested user\n namespaces and kernel uid/gid mappings allow elevation to root\n (CVE-2018-18955).\n\n The target system must have unprivileged user namespaces enabled and\n the newuidmap and newgidmap helpers installed (from uidmap package).\n\n This module has been tested successfully on:\n\n Fedora Workstation 28 kernel 4.16.3-301.fc28.x86_64;\n Kubuntu 18.04 LTS kernel 4.15.0-20-generic (x86_64);\n Linux Mint 19 kernel 4.15.0-20-generic (x86_64);\n Ubuntu Linux 18.04.1 LTS kernel 4.15.0-20-generic (x86_64).",
"disclosure_date": "2018-11-15",
"fullname": "exploit/linux/local/nested_namespace_idmap_limit_priv_esc",
"is_install_path": true,
"mod_time": "2026-05-14 11:43:36 +0000",
"name": "Linux Nested User Namespace idmap Limit Local Privilege Escalation",
"needs_cleanup": true,
"notes": {
"AKA": [
"subuid_shell.c"
],
"Reliability": [
"repeatable-session"
],
"SideEffects": [
"unknown-side-effects"
],
"Stability": [
"crash-safe"
]
},
"path": "/modules/exploits/linux/local/nested_namespace_idmap_limit_priv_esc.rb",
"platform": "Linux",
"post_auth": false,
"rank": 500,
"ref_name": "linux/local/nested_namespace_idmap_limit_priv_esc",
"references": [
"BID-105941",
"CVE-2018-18955",
"EDB-45886",
"PACKETSTORM-150381",
"URL-https://bugs.chromium.org/p/project-zero/issues/detail?id=1712",
"URL-https://github.com/bcoles/kernel-exploits/tree/master/CVE-2018-18955",
"URL-https://lwn.net/Articles/532593/",
"URL-https://bugs.launchpad.net/bugs/1801924",
"URL-https://people.canonical.com/~ubuntu-security/cve/CVE-2018-18955",
"URL-https://security-tracker.debian.org/tracker/CVE-2018-18955",
"URL-https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=d2f007dbe7e4c9583eea6eb04d60001e85c6f1bd",
"URL-https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.18.19",
"URL-https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.2"
],
"rport": null,
"session_types": [
"shell",
"meterpreter"
],
"targets": [
"Auto"
],
"type": "exploit"
} | — |
| Type type | Exploit-DB | localreceipt
What the source handed over{
"aliases": "",
"application_url": "",
"author": "Google Security Research",
"codes": "CVE-2018-18955",
"date_added": "2018-11-16",
"date_published": "2018-11-16",
"date_updated": "2018-11-16",
"description": "Linux - Broken uid/gid Mapping for Nested User Namespaces",
"file": "exploits/linux/local/45886.txt",
"id": "45886",
"platform": "linux",
"port": "",
"screenshot_url": "",
"source_url": "https://bugs.chromium.org/p/project-zero/issues/detail?id=1712",
"tags": "Local",
"type": "local",
"verified": "1"
} | — |
| Verified verified | Exploit-DB | falsereceipt
What the source handed over{
"aliases": "",
"application_url": "",
"author": "bcoles",
"codes": "CVE-2018-18955",
"date_added": "2019-07-26",
"date_published": "2018-11-21",
"date_updated": "2019-07-26",
"description": "Linux Kernel 4.15.x < 4.19.2 - 'map_write() CAP_SYS_ADMIN' Local Privilege Escalation (cron Method)",
"file": "exploits/linux/local/47164.sh",
"id": "47164",
"platform": "linux",
"port": "",
"screenshot_url": "",
"source_url": "https://github.com/bcoles/kernel-exploits/blob/4be5baae0135c9370420a21134f980b21a5ac1ab/CVE-2018-18955/exploit.cron.sh",
"tags": "",
"type": "local",
"verified": "0"
} | — |
| Verified verified | truereceipt
What the source handed over{
"aliases": "",
"application_url": "",
"author": "Google Security Research",
"codes": "CVE-2018-18955",
"date_added": "2018-11-16",
"date_published": "2018-11-16",
"date_updated": "2018-11-16",
"description": "Linux - Broken uid/gid Mapping for Nested User Namespaces",
"file": "exploits/linux/local/45886.txt",
"id": "45886",
"platform": "linux",
"port": "",
"screenshot_url": "",
"source_url": "https://bugs.chromium.org/p/project-zero/issues/detail?id=1712",
"tags": "Local",
"type": "local",
"verified": "1"
} | — |