Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

CVE-2018-7738

Published: 7 March 2018

In util-linux before 2.32-rc1, bash-completion/umount allows local users to gain privileges by embedding shell commands in a mountpoint name, which is mishandled during a umount command (within Bash) by a different user, as demonstrated by logging in as root and entering umount followed by a tab character for autocompletion.

Notes

AuthorNote
sbeattie
bash completion for umount moved from bash-completion to
util-linux in util-linux 2.28-1
mdeslaur
script in xenial bash-completion package isn't vulnerable
bash-completion package in bionic+ doesn't contain the umount
helper

Priority

Negligible

Cvss 3 Severity Score

7.8

Score breakdown

Status

Package Release Status
bash-completion
Launchpad, Ubuntu, Debian
artful Ignored
(end of life)
bionic Not vulnerable
(code not present)
cosmic Ignored
(end of life)
disco Ignored
(end of life)
eoan Ignored
(end of life)
focal Not vulnerable
(code not present)
trusty Not vulnerable

upstream Needs triage

xenial Not vulnerable

util-linux
Launchpad, Ubuntu, Debian
artful Ignored
(end of life)
bionic
Released (2.31.1-0.4ubuntu3.7)
cosmic Not vulnerable
(2.32-0.1ubuntu2)
disco Not vulnerable
(2.33.1-0.1ubuntu2)
eoan Not vulnerable
(2.33.1-0.1ubuntu2)
focal Not vulnerable
(2.33.1-0.1ubuntu2)
trusty Not vulnerable
(code not present)
upstream
Released (2.31.1-0.5)
xenial Not vulnerable
(code not present)
Patches:
upstream: https://github.com/karelzak/util-linux/commit/75f03badd7ed9f1dd951863d75e756883d3acc55

Severity score breakdown

Parameter Value
Base score 7.8
Attack vector Local
Attack complexity Low
Privileges required Low
User interaction None
Scope Unchanged
Confidentiality High
Integrity impact High
Availability impact High
Vector CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H