The manager_dispatch_notify_fd function in systemd allows local users to cause a denial of service (system hang) via a zero-length message received over a notify socket, which causes an error to be returned and the notification handler to be disabled.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade systemd-sysvUpgrade libgudev1-develUpgrade systemd-journal-gatewayUpgrade systemd-develUpgrade systemdUpgrade systemd-libsUpgrade libgudev1Upgrade systemd-debuginfoUpgrade systemd-python | Aug 28, 2019 | Oct 13, 2016 |
| Debian | — | Upgrade systemd | Mar 31, 2017 | Oct 13, 2016 |
| Redhat_linux | — | Upgrade systemd-journal-gatewayUpgrade systemdUpgrade systemd-debuginfoUpgrade systemd-develUpgrade systemd-libsUpgrade libgudev1-develUpgrade systemd-pythonUpgrade systemd-sysvUpgrade libgudev1 | Jan 7, 2017 | Oct 13, 2016 |
| Suse | — | Upgrade typelib-1_0-GUdev-1_0Upgrade libgudev-1_0-0-32bitUpgrade libudev-develUpgrade systemd-sysvinitUpgrade libudev1Upgrade libudev1-32bitUpgrade libgudev-1_0-develUpgrade systemdUpgrade systemd-bash-completionUpgrade sles12-docker-imageUpgrade systemd-32bitUpgrade sles12sp1-docker-imageUpgrade libgudev-1_0-0Upgrade udevUpgrade systemd-devel | Oct 14, 2016 | Oct 7, 2016 |
| Ubuntu | — | Upgrade systemd | Nov 19, 2024 | Oct 13, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub