CVE-2018-18955 is a privilege escalation vulnerability in the Linux kernel (versions 4.15.x through 4.19.x before 4.19.2) affecting the user namespace implementation. The flaw resides in the map_write() function in kernel/user_namespace.c, where improper handling of nested user namespaces with more than five UID or GID mapping extents leads to incorrect reverse ID transformation. This allows a user with CAP_SYS_ADMIN in a nested user namespace to bypass discretionary access controls (DAC) and gain unauthorized access to files outside the namespace, such as /etc/shadow. The vulnerability is triggered when more than five mapping extents are specified, causing access control checks (e.g., inode_owner_or_capable(), privileged_wrt_inode_uidgid()) to be bypassed due to invalid reverse mapping logic. The issue was introduced in commit 6397fac4915a and discovered by Jann Horn.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (6 hidden).
This repository contains a single Metasploit module (Ruby file) that exploits CVE-2018-18955, a local privilege escalation vulnerability in certain Linux kernel versions (4.15.0 to 4.18.18, 4.19.0 to 4.19.1). The exploit leverages broken uid/gid mappings in nested user namespaces to escalate privileges to root. The module checks for the presence and setuid bit of the 'newuidmap' and 'newgidmap' helpers, verifies kernel version and configuration, and then uploads and executes exploit binaries (either compiled on the target or pre-compiled). The exploit works by injecting a cron job into /etc/crontab to execute a payload as root, typically resulting in a root shell or meterpreter session. The module is weaponized, allowing for customizable payloads and automated cleanup. The only file in the repository is the Metasploit module itself, written in Ruby, and it is designed to be used within the Metasploit Framework.
This repository is a local privilege escalation exploit for CVE-2018-18955, targeting Linux kernel versions 4.15.x through 4.19.x before 4.19.2. The vulnerability lies in improper handling of nested user namespaces, allowing a user with CAP_SYS_ADMIN in a user namespace to escalate privileges and access resources outside the namespace. The repository provides multiple exploitation techniques, each implemented as a separate shell script: bash_completion, cron, dbus, ldpreload, and polkit. Each script compiles the necessary C payloads (subuid_shell.c, subshell.c, rootshell.c, libsubuid.c) and uses a different method to trigger the vulnerability and create a setuid root shell at /tmp/sh. The C files implement the core logic for namespace manipulation and payload execution. The exploit requires local access and specific system configurations (user namespaces, newuidmap/newgidmap utilities, and sometimes additional services like cron, dbus, or polkit). The repository is operational and provides a working local root exploit with multiple vectors for exploitation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.