CVE-2018-6553: AppArmor cupsd Sandbox Bypass Due to Use of Hard Links
Published Aug 10, 2018
·Updated
Last updated 25 August 2025
Other sources
The CUPS AppArmor profile incorrectly confined the dnssd backend due to use of hard links. A local attacker could possibly use this issue to escape confinement. This flaw affects versions prior to 2.2.7-1ubuntu2.1 in Ubuntu 18.04 LTS, prior to 2.2.4-7ubuntu3.1 in Ubuntu 17.10, prior to 2.1.3-4ubuntu0.5 in Ubuntu 16.04 LTS, and prior to 1.7.2-0ubuntu1.10 in Ubuntu 14.04 LTS.
— Launchpad
Affected Software
8 affected componentsFixes available
cups CUPS
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=17.10
Canonical Ubuntu Linux=18.04
Debian Debian Linux=8.0
Debian Debian Linux=9.0
debian/cups
2.3.3op2-3+deb11u82.3.3op2-3+deb11u102.4.2-3+deb12u92.4.10-3+deb13u22.4.10-3+deb13u12.4.16-1
Event History
Aug 10, 2018
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
DescriptionWeakness
Data Sourced
via NVD·03:29 PM
DescriptionSeverityAffected Software
Jan 11, 2024
Data Sourced
via Launchpad·11:09 PM
Description
Feb 19, 2026
Data Sourced
via Ubuntu·10:16 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·10:16 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2018-6553.
2
What is the severity rating of CVE-2018-6553?
The severity rating of CVE-2018-6553 is 8.8 (high).
3
How does CVE-2018-6553 affect Ubuntu 18.04 LTS?
CVE-2018-6553 affects Ubuntu 18.04 LTS versions prior to 2.2.7-1ubuntu2.1.
4
How does CVE-2018-6553 affect Ubuntu 17.10?
CVE-2018-6553 affects Ubuntu 17.10 versions prior to 2.2.4-7ubuntu3.1.
5
How does CVE-2018-6553 affect Ubuntu 14.04?
CVE-2018-6553 does not affect Ubuntu 14.04.