CVEs (55)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Fedoraproject NetappSystemd Project4Active Iq Unified Manager FedoraSolidfire & Hci Management Node+1 moreJun 17, 2026 Jun 3, 2020 N/A· v4 6.7 MEDIUM· v3 6.2 MEDIUM· v2 systemd through v245 mishandles numerical usernames such as ones composed of decimal digits or 0x followed by hex digits, as demonstrated by use of root privileges when privileges of the 0x0 user account were intended. N...Show more |
3Debian RedhatSystemd Project7Ceph Storage Debian LinuxDiscovery+4 moreJun 17, 2026 Mar 31, 2020 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 A heap use-after-free vulnerability was found in systemd before version v245-rc1, where asynchronous Polkit queries are performed while handling dbus messages. A local unprivileged attacker can abuse this flaw to crash s...Show more |
systemd 37-1 does not properly handle non-existent services, which causes a denial of service (failure of login procedure). |
5Canonical FedoraprojectNetapp+2 more7Active Iq Unified Manager Cloud BackupFedora+4 moreJun 17, 2026 Jan 21, 2020 N/A· v4 2.4 LOW· v3 2.1 LOW· v2 An issue was discovered in button_open in login/logind-button.c in systemd before 243. When executing the udevadm trigger command, a memory leak may occur. |
2Fedoraproject Systemd Project2Fedora SystemdNov 21, 2024 Oct 30, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 systemd 239 through 245 accepts any certificate signed by a trusted certificate authority for DNS Over TLS. Server Name Indication (SNI) is not sent, and there is no hostname validation with the GnuTLS backend. NOTE: Thi...Show more |
3Fedoraproject RedhatSystemd Project14Enterprise Linux Enterprise Linux EusEnterprise Linux For Ibm Z Systems 8 S390x+11 moreJun 17, 2026 Sep 4, 2019 N/A· v4 4.4 MEDIUM· v3 3.6 LOW· v2 In systemd 240, bus_open_system_watch_bind_with_description in shared/bus-util.c (as used by systemd-resolved to connect to the system D-Bus instance), calls sd_bus_set_trusted, which disables access controls for incomin...Show more |
2Netapp Systemd Project4Cn1610 Firmware SnapprotectSolidfire & Hci Management Node+1 moreMay 5, 2025 May 17, 2019 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 systemd 242 changes the VT1 mode upon a logout, which allows attackers to read cleartext passwords in certain circumstances, such as watching a shutdown, or using Ctrl-Alt-F1 and Ctrl-Alt-F2. This occurs because the KDGK...Show more |
3Canonical NetappSystemd Project6Cn1610 Firmware Hci Management NodeSnapprotect+3 moreJun 17, 2026 Apr 26, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 It was discovered that a systemd service that uses DynamicUser property can get new privileges through the execution of SUID binaries, which would allow to create binaries owned by the service transient group with the se...Show more |
4Canonical FedoraprojectNetapp+1 more7Cn1610 Firmware FedoraHci Management Node+4 moreJun 17, 2026 Apr 26, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 It was discovered that a systemd service that uses DynamicUser property can create a SUID/SGID binary that would be allowed to run as the transient service UID/GID even after the service is terminated. A local attacker m...Show more |
4Debian FedoraprojectRedhat+1 more4Debian Linux Enterprise LinuxFedora+1 moreJun 17, 2026 Apr 9, 2019 N/A· v4 7.0 HIGH· v3 4.4 MEDIUM· v2 In systemd before v242-rc4, it was discovered that pam_systemd does not properly sanitize the environment before using the XDG_SEAT variable. It is possible for an attacker, in some particular configurations, to set a XD...Show more |
8Canonical DebianFedoraproject+5 more22Active Iq Performance Analytics Services Debian LinuxEnterprise Linux+19 moreJun 17, 2026 Mar 21, 2019 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 An issue was discovered in sd-bus in systemd 239. bus_process_object() in libsystemd/sd-bus/bus-objects.c allocates a variable-length stack buffer for temporarily storing the object path of incoming D-Bus messages. An un...Show more |
4Canonical NetappRedhat+1 more5Active Iq Performance Analytics Services Element SoftwareEnterprise Linux+2 moreNov 21, 2024 Jan 14, 2019 N/A· v4 4.7 MEDIUM· v3 1.9 LOW· v2 It was discovered systemd does not correctly check the content of PIDFile files before using it to kill processes. When a service is run from an unprivileged user (e.g. User field set in the service file), a local attack...Show more |
5Canonical DebianOracle+2 more11Communications Session Border Controller Debian LinuxEnterprise Communications Broker+8 moreNov 21, 2024 Jan 11, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journald when many entries are sent to the journal socket. A local attacker, or a remo...Show more |
5Canonical DebianOracle+2 more11Communications Session Border Controller Debian LinuxEnterprise Communications Broker+8 moreNov 21, 2024 Jan 11, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journald when a program with long command line arguments calls syslog. A local attacke...Show more |
5Canonical DebianNetapp+2 more21Active Iq Performance Analytics Services Debian LinuxElement Software+18 moreNov 21, 2024 Jan 11, 2019 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 An out of bounds read was discovered in systemd-journald in the way it parses log messages that terminate with a colon ':'. A local attacker can use this flaw to disclose process memory data. Versions from v221 to v239 a...Show more |
4Canonical DebianRedhat+1 more9Debian Linux Enterprise Linux DesktopEnterprise Linux Server+6 moreJun 9, 2025 Oct 26, 2018 N/A· v4 8.8 HIGH· v3 5.8 MEDIUM· v2 A buffer overflow vulnerability in the dhcp6 client of systemd allows a malicious dhcp6 server to overwrite heap memory in systemd-networkd. Affected releases are systemd: versions up to and including 239. |
2Canonical Systemd Project2Systemd Ubuntu LinuxJun 9, 2025 Oct 26, 2018 N/A· v4 7.0 HIGH· v3 6.9 MEDIUM· v2 A race condition in chown_one() of systemd allows an attacker to cause systemd to set arbitrary permissions on arbitrary files. Affected releases are systemd versions up to and including 239. |
4Canonical DebianOracle+1 more4Communications Cloud Native Core Network Function Cloud Native Environment Debian LinuxSystemd+1 moreJun 9, 2025 Oct 26, 2018 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A vulnerability in unit_deserialize of systemd allows an attacker to supply arbitrary state across systemd re-execution via NotifyAccess. This can be used to improperly influence systemd execution and possibly lead to ro...Show more |
4Canonical DebianRedhat+1 more11Debian Linux Enterprise LinuxEnterprise Linux Aus+8 moreNov 21, 2024 Feb 16, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 In systemd prior to 234 a race condition exists between .mount and .automount units such that automount requests from kernel may not be serviced by systemd resulting in kernel holding the mountpoint and any processes tha...Show more |
3Canonical OpensuseSystemd Project3Leap SystemdUbuntu LinuxJun 17, 2026 Feb 13, 2018 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 systemd-tmpfiles in systemd through 237 mishandles symlinks present in non-terminal path components, which allows local users to obtain ownership of arbitrary files via vectors involving creation of a directory and a fil...Show more |