PT-2019-5811 · Red Hat+1 · Systemd-Journald+2

Riccardo Schirone

·

Published

2019-01-16

·

Updated

2023-02-12

·

CVE-2019-3815

CVSS v3.1

3.3

Low

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Red Hat Enterprise Linux versions since v219-62.2
Description A memory leak was discovered in the backport of fixes in Red Hat Enterprise Linux. The function dispatch message real() in journald-server.c does not free the memory allocated by set iovec field free() to store the CMDLINE= entry. A local attacker may use this flaw to make systemd-journald crash, resulting in a denial of service.
Recommendations For versions since v219-62.2, update to a version that includes the fix for the memory leak issue in the dispatch message real() function. As a temporary workaround, consider restricting access to the systemd-journald service to minimize the risk of exploitation.

Fix

Memory Leak

Weakness Enumeration

Related Identifiers

BDU:2021-03015
CESA-2019_0201
CVE-2019-3815
DLA-1711-1
RHSA-2019:0201
RHSA-2019_0201

Affected Products

Centos
Red Hat
Systemd-Journald