systemd through v245 mishandles numerical usernames such as ones composed of decimal digits or 0x followed by hex digits, as demonstrated by use of root privileges when privileges of the 0x0 user account were intended. NOTE: this issue exists because of an incomplete fix for CVE-2017-1000082.
CVSS Details
- CVSS 3.1 Base Score: 6.7
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade systemd-develUpgrade systemd-containerUpgrade systemd-libsUpgrade systemd-udevUpgrade systemdUpgrade systemd-journal-remoteUpgrade systemd-pamUpgrade systemd-tests | May 4, 2022 | Jun 3, 2020 |
| Amazon Linux Ami 2 | — | Upgrade systemd-resolvedUpgrade systemd-debuginfoUpgrade systemd-journal-gatewayUpgrade libgudev1-develUpgrade systemd-sysvUpgrade systemd-networkdUpgrade libgudev1Upgrade systemd-develUpgrade systemdUpgrade systemd-libsUpgrade systemd-python | Oct 11, 2022 | Jun 3, 2020 |
| Centos_linux | — | Upgrade systemd-tests-debuginfoUpgrade systemd-pamUpgrade systemd-journal-remote-debuginfoUpgrade systemd-debugsourceUpgrade systemd-develUpgrade systemd-pam-debuginfoUpgrade systemd-journal-remoteUpgrade systemd-libsUpgrade systemd-udevUpgrade systemd-testsUpgrade systemdUpgrade systemd-udev-debuginfoUpgrade systemd-container-debuginfoUpgrade systemd-containerUpgrade systemd-libs-debuginfoUpgrade systemd-debuginfo | Jun 1, 2021 | Jun 3, 2020 |
| Debian | — | Upgrade systemd | Jul 30, 2024 | Jun 3, 2020 |
| Huawei Euleros 2_0_sp8 | — | Upgrade systemd-journal-remoteUpgrade systemd-udev-compatUpgrade systemdUpgrade systemd-containerUpgrade systemd-udevUpgrade systemd-develUpgrade systemd-pamUpgrade systemd-libs | Feb 2, 2021 | Jun 3, 2020 |
| Huawei Euleros 2_0_sp9 | — | Upgrade systemd-containerUpgrade systemd-libsUpgrade systemd-udevUpgrade systemd-udev-compatUpgrade systemd | Feb 8, 2021 | Jun 3, 2020 |
| Oracle_linux | — | Upgrade systemdUpgrade systemd-develUpgrade systemd-journal-remoteUpgrade systemd-libsUpgrade systemd-testsUpgrade systemd-udevUpgrade systemd-pamUpgrade systemd-container | May 26, 2021 | May 31, 2020 |
| Redhat_linux | — | Upgrade systemd-debugsourceUpgrade systemd-pamUpgrade systemd-develUpgrade systemd-pam-debuginfoNo solution existsUpgrade systemd-tests-debuginfoUpgrade systemd-libsUpgrade systemd-udev-debuginfoUpgrade systemd-debuginfoUpgrade systemd-journal-remoteUpgrade systemd-journal-remote-debuginfoUpgrade systemd-container-debuginfoUpgrade systemd-testsUpgrade systemdUpgrade systemd-udevUpgrade systemd-containerUpgrade systemd-libs-debuginfo | May 21, 2021 | Jun 3, 2020 |
| Rocky_linux | — | Upgrade systemd-udev-debuginfoUpgrade systemd-udevUpgrade systemdUpgrade systemd-testsUpgrade systemd-debuginfoUpgrade systemd-libsUpgrade systemd-journal-remoteUpgrade systemd-container-debuginfoUpgrade systemd-develUpgrade systemd-tests-debuginfoUpgrade systemd-containerUpgrade systemd-debugsourceUpgrade systemd-pamUpgrade systemd-pam-debuginfoUpgrade systemd-libs-debuginfoUpgrade systemd-journal-remote-debuginfo | Mar 12, 2024 | Jun 3, 2020 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Jun 3, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub