The manager_dispatch_notify_fd function in systemd allows local users to cause a denial of service (system hang) via a zero-length message received over a notify socket, which causes an error to be returned and the notification handler to be disabled.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade systemd-journal-gatewayUpgrade systemd-sysvUpgrade systemd-develUpgrade libgudev1-develUpgrade systemd-debuginfoUpgrade systemd-libsUpgrade libgudev1Upgrade systemdUpgrade systemd-python | Aug 28, 2019 | Oct 13, 2016 |
| Debian | — | Upgrade systemd | Mar 31, 2017 | Oct 13, 2016 |
| Redhat_linux | — | Upgrade systemd-develUpgrade systemd-journal-gatewayUpgrade systemdUpgrade systemd-debuginfoUpgrade systemd-pythonUpgrade libgudev1-develUpgrade systemd-sysvUpgrade systemd-libsUpgrade libgudev1 | Jan 7, 2017 | Oct 13, 2016 |
| Suse | — | Upgrade systemd-bash-completionUpgrade libudev1Upgrade typelib-1_0-GUdev-1_0Upgrade libgudev-1_0-0-32bitUpgrade systemd-sysvinitUpgrade libgudev-1_0-develUpgrade libudev-develUpgrade systemdUpgrade libudev1-32bitUpgrade systemd-develUpgrade sles12sp1-docker-imageUpgrade libgudev-1_0-0Upgrade sles12-docker-imageUpgrade systemd-32bit | Oct 14, 2016 | Oct 7, 2016 |
| Ubuntu | — | Upgrade systemd | Nov 19, 2024 | Oct 13, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub