CVE-2018-6552: Apport treats the container PID as the global PID when /proc/<global_pid>/ is missing
Apport does not properly handle crashes originating from a PID namespace allowing local users to create certain files as root which an attacker could leverage to perform a denial of service via resource exhaustion, possibly gain root privileges, or escape from containers. The issamens() function returns True when /proc/<global pid>/ does not exist in order to indicate that the crash should be handled in the global namespace rather than inside of a container. However, the portion of the data/apport code that decides whether or not to forward a crash to a container does not always replace sys.argv[1] with the value stored in the hostpid variable when /proc/<global pid>/ does not exist which results in the container pid being used in the global namespace. This flaw affects versions 2.20.8-0ubuntu4 through 2.20.9-0ubuntu7, 2.20.7-0ubuntu3.7, 2.20.7-0ubuntu3.8, 2.20.1-0ubuntu2.15 through 2.20.1-0ubuntu2.17, and 2.14.1-0ubuntu3.28.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
apportto a version that resolves this vulnerability.Fixed in 2.20.9-0ubuntu7
Event History
Frequently Asked Questions
What is the severity of CVE-2018-6552?
CVE-2018-6552 has a medium severity level due to its potential to allow local users to create files as root.
How do I fix CVE-2018-6552?
To fix CVE-2018-6552, update Apport to its latest version that addresses this vulnerability.
What versions of Apport are affected by CVE-2018-6552?
CVE-2018-6552 primarily affects Apport versions 2.14.1, 2.20.1, 2.20.7, and 2.20.9.
Which Ubuntu versions are impacted by CVE-2018-6552?
CVE-2018-6552 impacts Ubuntu 14.04 LTS along with other Apport versions but does not affect Ubuntu 16.04, 17.10, or 18.04 LTS.
Can CVE-2018-6552 lead to privilege escalation?
Yes, CVE-2018-6552 can potentially lead to privilege escalation and resource exhaustion through local exploitation.