The Linux kernel, as used in Ubuntu 18.04 LTS and Ubuntu 18.10, allows local users to obtain names of files in which they would not normally be able to access via an overlayfs mount inside of a user namespace.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/105752 | third party advisory vdb entry |
https://usn.ubuntu.com/3836-2/ | third party advisory vendor advisory |
https://usn.ubuntu.com/3835-1/ | third party advisory vendor advisory |
https://people.canonical.com/~ubuntu-security/cve/2018/CVE-2018-6559.html | third party advisory |
https://lists.ubuntu.com/archives/kernel-team/2018-October/096172.html | third party advisory |
https://usn.ubuntu.com/3833-1/ | third party advisory vendor advisory |
https://usn.ubuntu.com/3832-1/ | third party advisory vendor advisory |
https://launchpad.net/bugs/1793458 | third party advisory issue tracking exploit |
https://usn.ubuntu.com/3836-1/ | third party advisory vendor advisory |