CVE-2018-13405: Canonical Ubuntu Linux

High severity, CVSS 7.8. EPSS: 1% chance of exploitation in the next 30 days.

The inode_init_owner function in fs/inode.c in the Linux kernel through 3.16 allows local users to create files with an unintended group ownership, in a scenario where a directory is SGID to a certain group and is writable by a user who is not a member of that group. Here, the non-member can trigger creation of a plain file whose group ownership is that group. The intended behavior was that the non-member can trigger creation of a directory (but not a plain file) whose group ownership is that group. The non-member can escalate privileges by making the plain file executable and SGID.

Affected products

  • Canonical Ubuntu Linux: version 14.04 only; version 16.04 only; version 18.04 only
  • Debian Debian Linux: version 8.0 only; version 9.0 only
  • F5 BIG-IP Access Policy Manager: from 13.0.0, before 13.1.3.5 (fixed in 13.1.3.5); from 14.0.0, before 14.1.3.1 (fixed in 14.1.3.1); from 15.0.0, before 15.0.1.4 (fixed in 15.0.1.4); version 15.1.0 only; version 16.0.0 only
  • F5 BIG-IP Advanced Firewall Manager: from 13.0.0, before 13.1.3.5 (fixed in 13.1.3.5); from 14.0.0, before 14.1.3.1 (fixed in 14.1.3.1); from 15.0.0, before 15.0.1.4 (fixed in 15.0.1.4); version 15.1.0 only; version 16.0.0 only
  • F5 BIG-IP Analytics: from 13.0.0, before 13.1.3.5 (fixed in 13.1.3.5); from 14.0.0, before 14.1.3.1 (fixed in 14.1.3.1); from 15.0.0, before 15.0.1.4 (fixed in 15.0.1.4); version 15.1.0 only; version 16.0.0 only
  • F5 BIG-IP Application Acceleration Manager: from 13.0.0, before 13.1.3.5 (fixed in 13.1.3.5); from 14.0.0, before 14.1.3.1 (fixed in 14.1.3.1); from 15.0.0, before 15.0.1.4 (fixed in 15.0.1.4); version 15.1.0 only; version 16.0.0 only
  • F5 BIG-IP Application Security Manager: from 13.0.0, before 13.1.3.5 (fixed in 13.1.3.5); from 14.0.0, before 14.1.3.1 (fixed in 14.1.3.1); from 15.0.0, before 15.0.1.4 (fixed in 15.0.1.4); version 15.1.0 only; version 16.0.0 only
  • F5 BIG-IP Domain Name System: from 13.0.0, before 13.1.3.5 (fixed in 13.1.3.5); from 14.0.0, before 14.1.3.1 (fixed in 14.1.3.1); from 15.0.0, before 15.0.1.4 (fixed in 15.0.1.4); version 15.1.0 only; version 16.0.0 only
  • F5 BIG-IP Edge Gateway: from 13.0.0, before 13.1.3.5 (fixed in 13.1.3.5); from 14.0.0, before 14.1.3.1 (fixed in 14.1.3.1); from 15.0.0, before 15.0.1.4 (fixed in 15.0.1.4); version 15.1.0 only; version 16.0.0 only
  • F5 BIG-IP Fraud Protection Service: from 13.0.0, before 13.1.3.5 (fixed in 13.1.3.5); from 14.0.0, before 14.1.3.1 (fixed in 14.1.3.1); from 15.0.0, before 15.0.1.4 (fixed in 15.0.1.4); version 15.1.0 only; version 16.0.0 only
  • F5 BIG-IP Global Traffic Manager: from 13.0.0, before 13.1.3.5 (fixed in 13.1.3.5); from 14.0.0, before 14.1.3.1 (fixed in 14.1.3.1); from 15.0.0, before 15.0.1.4 (fixed in 15.0.1.4); version 15.1.0 only; version 16.0.0 only
  • F5 BIG-IP Link Controller: from 13.0.0, before 13.1.3.5 (fixed in 13.1.3.5); from 14.0.0, before 14.1.3.1 (fixed in 14.1.3.1); from 15.0.0, before 15.0.1.4 (fixed in 15.0.1.4); version 15.1.0 only; version 16.0.0 only
  • F5 BIG-IP Local Traffic Manager: from 13.0.0, before 13.1.3.5 (fixed in 13.1.3.5); from 14.0.0, before 14.1.3.1 (fixed in 14.1.3.1); from 15.0.0, before 15.0.1.4 (fixed in 15.0.1.4); version 15.1.0 only; version 16.0.0 only
  • F5 BIG-IP Policy Enforcement Manager: from 13.0.0, before 13.1.3.5 (fixed in 13.1.3.5); from 14.0.0, before 14.1.3.1 (fixed in 14.1.3.1); from 15.0.0, before 15.0.1.4 (fixed in 15.0.1.4); version 15.1.0 only; version 16.0.0 only
  • F5 BIG-IP Webaccelerator: from 13.0.0, before 13.1.3.5 (fixed in 13.1.3.5); from 14.0.0, before 14.1.3.1 (fixed in 14.1.3.1); from 15.0.0, before 15.0.1.4 (fixed in 15.0.1.4); version 15.1.0 only; version 16.0.0 only
  • Fedoraproject Fedora: version 34 only; version 35 only
  • Linux Linux Kernel: up to and including 3.16
  • Red Hat Enterprise Linux Aus: version 7.4 only
  • Red Hat Enterprise Linux Desktop: version 6.0 only; version 7.0 only
  • Red Hat Enterprise Linux Eus: version 7.4 only; version 7.5 only
  • Red Hat Enterprise Linux For Real Time: version 7 only
  • Red Hat Enterprise Linux Server: version 6.0 only; version 7.0 only
  • Red Hat Enterprise Linux Server Aus: version 6.6 only; version 7.2 only; version 7.3 only
  • Red Hat Enterprise Linux Server Tus: version 7.2 only; version 7.3 only; version 7.4 only
  • Red Hat Enterprise Linux Workstation: version 6.0 only; version 7.0 only
  • and 2 more

Published 2018-07-06. Last modified 2026-06-17.