The manager_dispatch_notify_fd function in systemd allows local users to cause a denial of service (system hang) via a zero-length message received over a notify socket, which causes an error to be returned and the notification handler to be disabled.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade systemd-libsUpgrade systemd-debuginfoUpgrade systemd-pythonUpgrade systemdUpgrade libgudev1Upgrade systemd-journal-gatewayUpgrade systemd-develUpgrade systemd-sysvUpgrade libgudev1-devel | Aug 28, 2019 | Oct 13, 2016 |
| Debian | — | Upgrade systemd | Mar 31, 2017 | Oct 13, 2016 |
| Redhat_linux | — | Upgrade systemd-pythonUpgrade systemd-libsUpgrade libgudev1Upgrade systemd-sysvUpgrade libgudev1-develUpgrade systemd-develUpgrade systemd-debuginfoUpgrade systemdUpgrade systemd-journal-gateway | Jan 7, 2017 | Oct 13, 2016 |
| Suse | — | Upgrade systemdUpgrade libudev1-32bitUpgrade libudev-develUpgrade systemd-sysvinitUpgrade libudev1Upgrade typelib-1_0-GUdev-1_0Upgrade libgudev-1_0-0-32bitUpgrade systemd-bash-completionUpgrade libgudev-1_0-develUpgrade systemd-32bitUpgrade sles12sp1-docker-imageUpgrade systemd-develUpgrade sles12-docker-imageUpgrade udevUpgrade libgudev-1_0-0 | Oct 14, 2016 | Oct 7, 2016 |
| Ubuntu | — | Upgrade systemd | Nov 19, 2024 | Oct 13, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub