Lucene search

K
redhatcveRedhat.comRH:CVE-2018-13405
HistoryOct 20, 2019 - 12:07 p.m.

CVE-2018-13405

2019-10-2012:07:00
redhat.com
access.redhat.com
17

0.0004 Low

EPSS

Percentile

0.4%

A vulnerability was found in the fs/inode.c:inode_init_owner() function logic of the LInux kernel that allows local users to create files with an unintended group ownership and with group execution and SGID permission bits set, in a scenario where a directory is SGID and belongs to a certain group and is writable by a user who is not a member of this group. This can lead to excessive permissions granted in case when they should not.