VDB

DEBIAN-CVE-2018-7738

DEBIAN-CVE-2018-7738 PUBLISHED CVSS 7.800000190734863 HIGH

In util-linux before 2.32-rc1, bash-completion/umount allows local users to gain privileges by embedding shell commands in a mountpoint name, which is mishandled during a umount command (within Bash) by a different user, as demonstrated by logging in as root and entering umount followed by a tab character for autocompletion.

Risk Scores

CVSS v3.0
7.800000190734863
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
Debian:11bash-completion2.11-5, 2.11-7, 2.11-8
Debian:13util-linux0, 0, 0
Debian:12bash-completion1:2.14.0-1, 0, 2.11-6
Debian:12util-linux0, 0, 0
Debian:13bash-completion1:2.16.0-7, 0, 2.16.0-7
Debian:11util-linux0, 0, 0
Debian:14bash-completion0, 0, 1:2.16.0-8
Debian:14util-linux0, 0, 0

Timeline

  • Mar 7, 2018 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›