CVE-2018-19333

NameCVE-2018-19333
Descriptionpkg/sentry/kernel/shm/shm.go in Google gVisor before 2018-11-01 allows attackers to overwrite memory locations in processes running as root (but not escape the sandbox) via vectors involving IPC_RMID shmctl calls, because reference counting is mishandled.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
golang-gvisor-gvisor (PTS)bookworm0.0~20221219.0-2fixed
trixie0.0~20240729.0-4fixed
forky, sid0.0~20240729.0-7fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
golang-gvisor-gvisorsource(unstable)(not affected)

Notes

- golang-gvisor-gvisor <not-affected> (Fixed before initial upload to Debian)
Fixed by: https://github.com/google/gvisor/commit/0e277a39c8b6f905e289b75e8ad0594e6b3562ca (release-20190304.1)

Search for package or bug name: Reporting problems