VulnerabilityModified
CVE-2018-6559
The Linux kernel, as used in Ubuntu 18.04 LTS and Ubuntu 18.10, allows local users to obtain names of files in which they would not normally be able to access via an overlayfs mount inside of a user namespace.
LOW 3.3EPSS 0.53%
Does this matter?
Lower severity and a low EPSS score (0.53%). Track it; it rarely justifies an emergency change on its own.
Description
The Linux kernel, as used in Ubuntu 18.04 LTS and Ubuntu 18.10, allows local users to obtain names of files in which they would not normally be able to access via an overlayfs mount inside of a user namespace.
- CVSS 3.0
- 3.3 LOWCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 0.53% probability · 43th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- linux/linux kernel · canonical/ubuntu linux
- Source
- security@ubuntu.com
References
- http://www.securityfocus.com/bid/105752Third Party Advisory, VDB Entry
- https://launchpad.net/bugs/1793458Exploit, Issue Tracking, Third Party Advisory
- https://lists.ubuntu.com/archives/kernel-team/2018-October/096172.htmlThird Party Advisory
- https://people.canonical.com/~ubuntu-security/cve/2018/CVE-2018-6559.htmlThird Party Advisory
- https://usn.ubuntu.com/3832-1/Third Party Advisory
- https://usn.ubuntu.com/3833-1/Third Party Advisory
- https://usn.ubuntu.com/3835-1/Third Party Advisory
- https://usn.ubuntu.com/3836-1/Third Party Advisory
- https://usn.ubuntu.com/3836-2/Third Party Advisory
- http://www.securityfocus.com/bid/105752Third Party Advisory, VDB Entry
- https://launchpad.net/bugs/1793458Exploit, Issue Tracking, Third Party Advisory
- https://lists.ubuntu.com/archives/kernel-team/2018-October/096172.htmlThird Party Advisory
- https://people.canonical.com/~ubuntu-security/cve/2018/CVE-2018-6559.htmlThird Party Advisory
- https://usn.ubuntu.com/3832-1/Third Party Advisory
- https://usn.ubuntu.com/3833-1/Third Party Advisory
- https://usn.ubuntu.com/3835-1/Third Party Advisory
- https://usn.ubuntu.com/3836-1/Third Party Advisory
- https://usn.ubuntu.com/3836-2/Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.