PT-2018-2799 · Systemd+5 · Systemd+5
Jann Horn
·
Published
2018-10-26
·
Updated
2024-06-15
·
CVE-2018-15686
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
systemd versions up to and including 239
Description
A vulnerability in
unit deserialize of systemd allows an attacker to supply arbitrary state across systemd re-execution via NotifyAccess. This can be used to improperly influence systemd execution and possibly lead to root privilege escalation.Recommendations
For systemd versions up to and including 239, update to a version higher than 239 to resolve the issue.
As a temporary workaround, consider restricting access to
NotifyAccess to minimize the risk of exploitation.Exploit
Fix
Deserialization of Untrusted Data
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Centos
Red Hat
Suse
Ubuntu
Systemd