← Back

Systemd

systemd

Vendor: Systemd Project • 55 CVEs

CVEs (55)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Debian
OpensuseSystemd Project
3Debian Linux
LeapSystemd
Nov 21, 2024
Jan 29, 2018
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
systemd-tmpfiles in systemd before 237 attempts to support ownership/permission changes on hardlinked files even if the fs.protected_hardlinks sysctl is turned off, which allows local users to bypass intended access rest...Show more
systemd-tmpfiles in systemd before 237 attempts to support ownership/permission changes on hardlinked files even if the fs.protected_hardlinks sysctl is turned off, which allows local users to bypass intended access restrictions via vectors involving a hard link to a file for which the user lacks write access, as demonstrated by changing the ownership of the /etc/passwd file.Show less
2Canonical
Systemd Project
2Systemd
Ubuntu Linux
May 13, 2026
Oct 26, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In systemd 223 through 235, a remote DNS server can respond with a custom crafted DNS NSEC resource record to trigger an infinite loop in the dns_packet_read_type_window() function of the 'systemd-resolved' service and c...Show more
In systemd 223 through 235, a remote DNS server can respond with a custom crafted DNS NSEC resource record to trigger an infinite loop in the dns_packet_read_type_window() function of the 'systemd-resolved' service and cause a DoS of the affected service.Show less
1Systemd Project
1Systemd
May 13, 2026
Sep 25, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Stack-based buffer overflow in the getpwnam and getgrnam functions of the NSS module nss-mymachines in systemd.
1Systemd Project
1Systemd
May 13, 2026
Jul 7, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
systemd v233 and earlier fails to safely parse usernames starting with a numeric digit (e.g. "0day"), running the service in question with root privileges rather than the user intended.
1Systemd Project
1Systemd
May 13, 2026
Jun 28, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In systemd through 233, certain sizes passed to dns_packet_new in systemd-resolved can cause it to allocate a buffer that's too small. A malicious DNS server can exploit this via a response with a specially crafted TCP p...Show more
In systemd through 233, certain sizes passed to dns_packet_new in systemd-resolved can cause it to allocate a buffer that's too small. A malicious DNS server can exploit this via a response with a specially crafted TCP payload to trick systemd-resolved into allocating a buffer that's too small, and subsequently write arbitrary data beyond the end of it.Show less
1Systemd Project
1Systemd
May 13, 2026
May 24, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
systemd-resolved through 233 allows remote attackers to cause a denial of service (daemon crash) via a crafted DNS response with an empty question section.
1Systemd Project
1Systemd
May 13, 2026
Jan 23, 2017
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
A flaw in systemd v228 in /src/basic/fs-util.c caused world writable suid files to be created when using the systemd timers features, allowing local attackers to escalate their privileges to root. This is fixed in v229.
3Novell
RedhatSystemd Project
9Enterprise Linux Desktop
Enterprise Linux Hpc NodeEnterprise Linux Server+6 more
May 6, 2026
Oct 13, 2016
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
The manager_dispatch_notify_fd function in systemd allows local users to cause a denial of service (system hang) via a zero-length message received over a notify socket, which causes an error to be returned and the notif...Show more
The manager_dispatch_notify_fd function in systemd allows local users to cause a denial of service (system hang) via a zero-length message received over a notify socket, which causes an error to be returned and the notification handler to be disabled.Show less
2Canonical
Systemd Project
2Systemd
Ubuntu Linux
May 6, 2026
Oct 13, 2016
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
The manager_invoke_notify_message function in systemd 231 and earlier allows local users to cause a denial of service (assertion failure and PID 1 hang) via a zero-length message received over a notify socket.
2Opensuse
Systemd Project
2Opensuse
Systemd
May 6, 2026
Apr 18, 2014
N/A· v4
N/A· v3
6.3 MEDIUM· v2
The session_link_x11_socket function in login/logind-session.c in systemd-logind in systemd, possibly 37 and earlier, allows local users to create or overwrite arbitrary files via a symlink attack on the X11 user directo...Show more
The session_link_x11_socket function in login/logind-session.c in systemd-logind in systemd, possibly 37 and earlier, allows local users to create or overwrite arbitrary files via a symlink attack on the X11 user directory in /run/user/.Show less
2Debian
Systemd Project
2Debian Linux
Systemd
Apr 29, 2026
Oct 28, 2013
N/A· v4
N/A· v3
5.9 MEDIUM· v2
The SetX11Keyboard function in systemd, when PolicyKit Local Authority (PKLA) is used to change the group permissions on the X Keyboard Extension (XKB) layouts description, allows local users in the group to modify the X...Show more
The SetX11Keyboard function in systemd, when PolicyKit Local Authority (PKLA) is used to change the group permissions on the X Keyboard Extension (XKB) layouts description, allows local users in the group to modify the Xorg X11 Server configuration file and possibly gain privileges via vectors involving "special and control characters."Show less
1Systemd Project
1Systemd
Apr 29, 2026
Oct 28, 2013
N/A· v4
N/A· v3
2.1 LOW· v2
journald in systemd, when the origin of native messages is set to file, allows local users to cause a denial of service (logging service blocking) via a crafted file descriptor.
1Systemd Project
1Systemd
Apr 29, 2026
Oct 28, 2013
N/A· v4
5.0 MEDIUM· v3
3.3 LOW· v2
systemd, when updating file permissions, allows local users to change the permissions and SELinux security contexts for arbitrary files via a symlink attack on unspecified files.
2Debian
Systemd Project
2Debian Linux
Systemd
Apr 29, 2026
Oct 28, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
Integer overflow in the valid_user_field function in journal/journald-native.c in systemd allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large journal data field, w...Show more
Integer overflow in the valid_user_field function in journal/journald-native.c in systemd allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large journal data field, which triggers a heap-based buffer overflow.Show less
3Canonical
DebianSystemd Project
3Debian Linux
SystemdUbuntu Linux
Apr 29, 2026
Oct 3, 2013
N/A· v4
N/A· v3
6.9 MEDIUM· v2
systemd does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setu...Show more
systemd does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process, a related issue to CVE-2013-4288.Show less