PT-2019-5811 · Red Hat+1 · Systemd-Journald+2
Riccardo Schirone
·
Published
2019-01-16
·
Updated
2023-02-12
·
CVE-2019-3815
CVSS v3.1
3.3
Low
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
Red Hat Enterprise Linux versions since v219-62.2
Description
A memory leak was discovered in the backport of fixes in Red Hat Enterprise Linux. The function
dispatch message real() in journald-server.c does not free the memory allocated by set iovec field free() to store the CMDLINE= entry. A local attacker may use this flaw to make systemd-journald crash, resulting in a denial of service.Recommendations
For versions since v219-62.2, update to a version that includes the fix for the memory leak issue in the
dispatch message real() function. As a temporary workaround, consider restricting access to the systemd-journald service to minimize the risk of exploitation.Fix
Memory Leak
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Centos
Red Hat
Systemd-Journald