PT-2021-3825 · Systemd+9 · Systemd+9

Keszybz

·

Published

2021-06-09

·

Updated

2026-03-10

·

CVE-2021-33910

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions systemd versions prior to 246.15 systemd versions prior to 247.8 systemd versions prior to 248.5 systemd versions prior to 249.1
Description The issue is related to uncontrolled resource consumption in the systemd initialization and service management subsystem, specifically in the functions alloca() and strdup(). This can be exploited by an attacker to cause a denial of service, potentially leading to an operating system crash. The vulnerability involves a memory allocation with an excessive size value, where a local attacker can control the pathname, utilizing strdupa and alloca functions.
Recommendations For versions prior to 246.15, update to version 246.15 or later. For versions prior to 247.8, update to version 247.8 or later. For versions prior to 248.5, update to version 248.5 or later. For versions prior to 249.1, update to version 249.1 or later.

Exploit

Fix

Resource Exhaustion

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

ALT-PU-2021-2285
ALT-PU-2021-2318
ALT-PU-2021-2328
ALT-PU-2021-2584
BDU:2021-04153
CESA-2021_2717
CVE-2021-33910
DLA-2715-1
DSA-4942-1
MGASA-2021-0365
OESA-2021-1271
OPENSUSE-SU-2021:1082-1
OPENSUSE-SU-2021:1370-1
OPENSUSE-SU-2021:2404-1
OPENSUSE-SU-2021:2410-1
OPENSUSE-SU-2021:2809-1
OPENSUSE-SU-2021:3348-1
OPENSUSE-SU-2021_1082-1
OPENSUSE-SU-2021_1370-1
OPENSUSE-SU-2021_2404-1
OPENSUSE-SU-2021_2410-1
OPENSUSE-SU-2021_2809-1
OPENSUSE-SU-2021_3348-1
OPENSUSE-SU-2024:11420-1
OPENSUSE-SU-2024:11679-1
RHSA-2021:2717
RHSA-2021:2721
RHSA-2021:2724
RHSA-2021:2736
RHSA-2021_2717
RLSA-2021:2717
ROSA-SA-2024-2470
SUSE-SU-2021:2404-1
SUSE-SU-2021:2405-1
SUSE-SU-2021:2410-1
SUSE-SU-2021:2423-1
SUSE-SU-2021:2809-1
SUSE-SU-2021:3348-1
SUSE-SU-2021:3611-1
SUSE-SU-2021_2404-1
SUSE-SU-2021_2405-1
SUSE-SU-2021_2410-1
SUSE-SU-2021_2423-1
SUSE-SU-2021_3348-1
SUSE-SU-2021_3611-1
USN-5013-1
USN-5013-2

Affected Products

Alt Linux
Astra Linux
Centos
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu
Systemd