CVE Vulnerabilities

CVE-2018-7738

Published: Mar 07, 2018 | Modified: Sep 25, 2020
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
6.7 MODERATE
CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
Ubuntu
NEGLIGIBLE

In util-linux before 2.32-rc1, bash-completion/umount allows local users to gain privileges by embedding shell commands in a mountpoint name, which is mishandled during a umount command (within Bash) by a different user, as demonstrated by logging in as root and entering umount followed by a tab character for autocompletion.

Affected Software

Name Vendor Start Version End Version
Util-linux Kernel * 2.31 (including)
Bash-completion Ubuntu artful *
Bash-completion Ubuntu cosmic *
Bash-completion Ubuntu disco *
Bash-completion Ubuntu eoan *
Bash-completion Ubuntu trusty *
Util-linux Ubuntu artful *
Util-linux Ubuntu bionic *
Util-linux Ubuntu trusty *
Util-linux Ubuntu upstream *

References