PT-2018-2289 · Systemd+5 · Systemd-Journald+6

Matthias Kaiser

·

Published

2018-11-27

·

Updated

2025-06-27

·

CVE-2018-16865

CVSS v2.0

7.6

High

VectorAV:N/AC:H/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions systemd-journald versions through v240 systemd-journal-remote versions through v240
Description The issue is caused by an unbounded memory allocation in the systemd-journald and systemd-journal-remote binary system, which can lead to a stack clash with another memory region. This can be exploited by a local or remote attacker to crash systemd-journald or execute code with journald privileges.
Recommendations For versions through v240, consider disabling the systemd-journald service until a patch is available to prevent potential exploitation. Restrict access to the systemd-journal-remote service to minimize the risk of remote exploitation. Avoid sending a large number of entries to the journal socket to prevent crashing systemd-journald. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Allocation of Resources Without Limits

Buffer Overflow

Weakness Enumeration

Related Identifiers

ALT-PU-2019-1023
ALT-PU-2019-1260
BDU:2019-00412
BDU:2019-00413
BDU:2019-01751
CESA-2019_0049
CVE-2018-16865
DLA-1639-1
DSA-4367-1
DSA-4367-2
OPENSUSE-SU-2019:0098-1
OPENSUSE-SU-2019_0097-1
OPENSUSE-SU-2019_0098-1
OPENSUSE-SU-2024:11420-1
RHSA-2019:0049
RHSA-2019:0204
RHSA-2019:0271
RHSA-2019:0342
RHSA-2019:0361
RHSA-2019:2402
RHSA-2019_0049
SUSE-SU-2019:0053-1
SUSE-SU-2019:0054-1
SUSE-SU-2019:0054-2
SUSE-SU-2019:0135-1
SUSE-SU-2019:0137-1
USN-3855-1

Affected Products

Alt Linux
Centos
Red Hat
Suse
Ubuntu
Systemd-Journal-Remote
Systemd-Journald