Medium severity5.3NVD Advisory· Published Feb 15, 2018· Updated Jun 17, 2026
CVE-2018-7169
CVE-2018-7169
Description
An issue was discovered in shadow 4.5. newgidmap (in shadow-utils) is setuid and allows an unprivileged user to be placed in a user namespace where setgroups(2) is permitted. This allows an attacker to remove themselves from a supplementary group, which may allow access to certain filesystem paths if the administrator has used "group blacklisting" (e.g., chmod g-rwx) to restrict access to paths. This flaw effectively reverts a security feature in the kernel (in particular, the /proc/self/setgroups knob) to prevent this sort of privilege escalation.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
10- cpe:2.3:a:shadow_project:shadow:4.5:*:*:*:*:*:*:*
- Range: <=4.5
- osv-coords8 versionspkg:rpm/opensuse/shadow&distro=openSUSE%20Tumbleweedpkg:rpm/suse/shadow&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP2pkg:rpm/suse/shadow&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP3pkg:rpm/suse/shadow&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2pkg:rpm/suse/shadow&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3pkg:rpm/suse/shadow&distro=SUSE%20Linux%20Enterprise%20Server%20for%20Raspberry%20Pi%2012%20SP2pkg:rpm/suse/shadow&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP2pkg:rpm/suse/shadow&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP3
< 4.9-1.1+ 7 more
- (no CPE)range: < 4.9-1.1
- (no CPE)range: < 4.2.1-27.6.1
- (no CPE)range: < 4.2.1-27.6.1
- (no CPE)range: < 4.2.1-27.6.1
- (no CPE)range: < 4.2.1-27.6.1
- (no CPE)range: < 4.2.1-27.6.1
- (no CPE)range: < 4.2.1-27.6.1
- (no CPE)range: < 4.2.1-27.6.1
Patches
Vulnerability mechanics
References
2- bugs.launchpad.net/ubuntu/+source/shadow/+bug/1729357nvdExploitIssue TrackingThird Party Advisory
- security.gentoo.org/glsa/201805-09nvdThird Party Advisory
News mentions
0No linked articles in our index yet.