In systemd through 233, certain sizes passed to dns_packet_new in systemd-resolved can cause it to allocate a buffer that's too small. A malicious DNS server can exploit this via a response with a specially crafted TCP payload to trick systemd-resolved into allocating a buffer that's too small, and subsequently write arbitrary data beyond the end of it.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Jun 28, 2017 |
| Debian | — | Upgrade systemd | Jul 30, 2024 | Jun 28, 2017 |
| Huawei Euleros 2_0_sp3 | — | Upgrade libgudev1Upgrade libgudev1-develUpgrade systemd-libsUpgrade systemd-sysvUpgrade systemd-pythonUpgrade systemdUpgrade systemd-devel | Apr 30, 2021 | Jun 28, 2017 |
| Huawei Euleros 2_0_sp5 | — | Upgrade systemd-develUpgrade systemd-libsUpgrade systemd-sysvUpgrade systemdUpgrade systemd-python | Feb 15, 2019 | Jun 28, 2017 |
| Suse | — | Upgrade udevUpgrade systemd-develUpgrade dracutUpgrade sles12sp2-docker-imageUpgrade systemdUpgrade systemd-docUpgrade dracut-fipsUpgrade libudev-develUpgrade libudev1Upgrade systemd-32bitUpgrade libsystemd0-32bitUpgrade systemd-bash-completionUpgrade systemd-coredumpUpgrade systemd-containerUpgrade systemd-langUpgrade systemd-journal-remoteUpgrade libsystemd0Upgrade systemd-sysvinitUpgrade libudev1-32bit | Jul 19, 2017 | Jun 28, 2017 |
| Ubuntu | — | Upgrade systemd | Jun 29, 2017 | Jun 27, 2017 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Jun 28, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub