systemd through v245 mishandles numerical usernames such as ones composed of decimal digits or 0x followed by hex digits, as demonstrated by use of root privileges when privileges of the 0x0 user account were intended. NOTE: this issue exists because of an incomplete fix for CVE-2017-1000082.
CVSS Details
- CVSS 3.1 Base Score: 6.7
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade systemd-develUpgrade systemd-containerUpgrade systemd-libsUpgrade systemdUpgrade systemd-journal-remoteUpgrade systemd-pamUpgrade systemd-udevUpgrade systemd-tests | May 4, 2022 | Jun 3, 2020 |
| Amazon Linux Ami 2 | — | Upgrade systemd-debuginfoUpgrade systemd-journal-gatewayUpgrade systemd-sysvUpgrade systemd-networkdUpgrade libgudev1-develUpgrade systemd-resolvedUpgrade systemdUpgrade systemd-libsUpgrade systemd-pythonUpgrade libgudev1Upgrade systemd-devel | Oct 11, 2022 | Jun 3, 2020 |
| Centos_linux | — | Upgrade systemd-testsUpgrade systemd-libsUpgrade systemd-libs-debuginfoUpgrade systemd-containerUpgrade systemd-container-debuginfoUpgrade systemd-udevUpgrade systemdUpgrade systemd-debuginfoUpgrade systemd-udev-debuginfoUpgrade systemd-pamUpgrade systemd-debugsourceUpgrade systemd-tests-debuginfoUpgrade systemd-journal-remoteUpgrade systemd-develUpgrade systemd-pam-debuginfoUpgrade systemd-journal-remote-debuginfo | Jun 1, 2021 | Jun 3, 2020 |
| Debian | — | Upgrade systemd | Jul 30, 2024 | Jun 3, 2020 |
| Huawei Euleros 2_0_sp8 | — | Upgrade systemd-develUpgrade systemdUpgrade systemd-udev-compatUpgrade systemd-containerUpgrade systemd-udevUpgrade systemd-journal-remoteUpgrade systemd-libsUpgrade systemd-pam | Feb 2, 2021 | Jun 3, 2020 |
| Huawei Euleros 2_0_sp9 | — | Upgrade systemd-udev-compatUpgrade systemd-udevUpgrade systemdUpgrade systemd-libsUpgrade systemd-container | Feb 8, 2021 | Jun 3, 2020 |
| Oracle_linux | — | Upgrade systemd-libsUpgrade systemd-pamUpgrade systemd-containerUpgrade systemd-udevUpgrade systemd-testsUpgrade systemd-journal-remoteUpgrade systemdUpgrade systemd-devel | May 26, 2021 | May 31, 2020 |
| Redhat_linux | — | Upgrade systemd-testsUpgrade systemd-tests-debuginfoUpgrade systemd-container-debuginfoUpgrade systemdUpgrade systemd-journal-remoteUpgrade systemd-libsUpgrade systemd-libs-debuginfoUpgrade systemd-udevUpgrade systemd-containerUpgrade systemd-debuginfoUpgrade systemd-udev-debuginfoUpgrade systemd-journal-remote-debuginfoUpgrade systemd-pam-debuginfoUpgrade systemd-pamNo solution existsUpgrade systemd-develUpgrade systemd-debugsource | May 21, 2021 | Jun 3, 2020 |
| Rocky_linux | — | Upgrade systemd-pam-debuginfoUpgrade systemd-develUpgrade systemd-journal-remote-debuginfoUpgrade systemd-debugsourceUpgrade systemd-tests-debuginfoUpgrade systemd-libs-debuginfoUpgrade systemd-pamUpgrade systemd-containerUpgrade systemd-testsUpgrade systemd-udevUpgrade systemd-udev-debuginfoUpgrade systemd-journal-remoteUpgrade systemdUpgrade systemd-libsUpgrade systemd-container-debuginfoUpgrade systemd-debuginfo | Mar 12, 2024 | Jun 3, 2020 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Jun 3, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub