SB2018102617 - Information exposure in Linux kernel
Published: October 26, 2018
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Information exposure (CVE-ID: CVE-2018-6559)
The vulnerability allows a local user to gain access to sensitive information.
The Linux kernel, as used in Ubuntu 18.04 LTS and Ubuntu 18.10, allows local users to obtain names of files in which they would not normally be able to access via an overlayfs mount inside of a user namespace.
Remediation
Install update from vendor's website.
References
- http://www.securityfocus.com/bid/105752
- https://launchpad.net/bugs/1793458
- https://lists.ubuntu.com/archives/kernel-team/2018-October/096172.html
- https://people.canonical.com/~ubuntu-security/cve/2018/CVE-2018-6559.html
- https://usn.ubuntu.com/3832-1/
- https://usn.ubuntu.com/3833-1/
- https://usn.ubuntu.com/3835-1/
- https://usn.ubuntu.com/3836-1/
- https://usn.ubuntu.com/3836-2/