ZeroHour

CVE-2019-6454

PoC
CVSS 3.1
5.5 medium
EPSS
2%p80
Published
()
Modified
Description

An issue was discovered in sd-bus in systemd 239. bus_process_object() in libsystemd/sd-bus/bus-objects.c allocates a variable-length stack buffer for temporarily storing the object path of incoming D-Bus messages. An unprivileged local user can exploit this by sending a specially crafted message to PID1, causing the stack pointer to jump over the stack guard pages into an unmapped memory region and trigger a denial of service (systemd PID1 crash and kernel panic).

Vendors
systemd projectopensusenetappdebianfedoraprojectcanonicalredhatmcafee
Products
systemd, leap, active iq performance analytics services, debian linux, fedora, ubuntu linux, enterprise linux, enterprise linux compute node eus, enterprise linux desktop, enterprise linux eus, enterprise linux for ibm z systems eus, enterprise linux for power big endian eus
Weakness
CWE-787
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.