CVE-2018-15686
published 2018-10-26CVE-2018-15686: A vulnerability in unit_deserialize of systemd allows an attacker to supply arbitrary state across systemd re-execution via NotifyAccess. This can be used to…
PriorityP348high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EXPLOIT
EPSS
2.28%
81.2th percentile
A vulnerability in unit_deserialize of systemd allows an attacker to supply arbitrary state across systemd re-execution via NotifyAccess. This can be used to improperly influence systemd execution and possibly lead to root privilege escalation. Affected releases are systemd versions up to and including 239.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | systemd | < systemd 239-12 (bookworm) | systemd 239-12 (bookworm) |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cm1_systemd_239-31_on_cbl_mariner_1.0 | — | — |
| oracle | communications_cloud_native_core_network_function_cloud_native_environment | — | — |
| systemd | systemd | unspecified – 239 | — |
| systemd_project | systemd | <= 239 | — |
| systemd_project | systemd | >= 0 < 239-12 | 239-12 |
| systemd_project | systemd | >= 0 < 239-12 | 239-12 |
| systemd_project | systemd | >= 0 < 239-12 | 239-12 |
| systemd_project | systemd | >= 0 < 239-12 | 239-12 |
| systemd_project | systemd | >= 0 < 229-4ubuntu21.9 | 229-4ubuntu21.9 |
| systemd_project | systemd | >= 0 < 229-4ubuntu21.10 | 229-4ubuntu21.10 |
| systemd_project | systemd | >= 0 < 229-4ubuntu21.8 | 229-4ubuntu21.8 |
| systemd_project | systemd | >= 0 < 237-3ubuntu10.9 | 237-3ubuntu10.9 |
| systemd_project | systemd | >= 0 < 237-3ubuntu10.6 | 237-3ubuntu10.6 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv3.07.0HIGHCVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
vendor_oracle6.3HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Communications Risk Matrix: Signaling (Calico) — CVE-2018-15686
vendor_oracle·2021-07-15·CVSS 6.3
CVE-2018-15686 [HIGH] Oracle Oracle Communications Risk Matrix: Signaling (Calico) — CVE-2018-15686
Oracle Oracle Communications Risk Matrix: Signaling (Calico) vulnerability
CVE: CVE-2018-15686
CVSS: 6.3
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpujul2021 (JUL 2021)
Ubuntu
systemd regression
vendor_ubuntu·2018-11-27·CVSS 7.8
CVE-2018-6954 [HIGH] systemd regression
Title: systemd regression
Summary: USN-3816-1 caused a regression in systemd-tmpfiles.
USN-3816-1 fixed vulnerabilities in systemd. The fix for CVE-2018-6954
caused a regression in systemd-tmpfiles when running Ubuntu inside a
container on some older kernels. This issue only affected Ubuntu 16.04
LTS. In order to continue to support this configuration, the fixes for
CVE-2018-6954 have been reverted.
We apologize for the inconvenience.
Original advisory details:
Jann Horn discovered that unit_deserialize incorrectly handled status messages
above a certain length. A local attacker could potentially exploit this via
NotifyAccess to inject arbitrary state across re-execution and obtain root
privileges. (CVE-2018-15686)
Jann Horn discovered a race condition in chown_one(). A local attacke
Ubuntu
systemd vulnerability
vendor_ubuntu·2018-11-19·CVSS 7.8
CVE-2018-6954 [HIGH] systemd vulnerability
Title: systemd vulnerability
Summary: systemd-tmpfiles could be made to change ownership of arbitrary files.
USN-3816-1 fixed several vulnerabilities in systemd. However, the fix for
CVE-2018-6954 was not sufficient. This update provides the remaining fixes.
We apologize for the inconvenience.
Original advisory details:
Jann Horn discovered that unit_deserialize incorrectly handled status messages
above a certain length. A local attacker could potentially exploit this via
NotifyAccess to inject arbitrary state across re-execution and obtain root
privileges. (CVE-2018-15686)
Jann Horn discovered a race condition in chown_one(). A local attacker
could potentially exploit this by setting arbitrary permissions on certain
files to obtain root privileges. This issue only affected Ubuntu 18
Ubuntu
systemd vulnerabilities
vendor_ubuntu·2018-11-12·CVSS 7.8
CVE-2018-15686 [HIGH] systemd vulnerabilities
Title: systemd vulnerabilities
Summary: Several security issues were fixed in systemd.
Jann Horn discovered that unit_deserialize incorrectly handled status messages
above a certain length. A local attacker could potentially exploit this via
NotifyAccess to inject arbitrary state across re-execution and obtain root
privileges. (CVE-2018-15686)
Jann Horn discovered a race condition in chown_one(). A local attacker
could potentially exploit this by setting arbitrary permissions on certain
files to obtain root privileges. This issue only affected Ubuntu 18.04 LTS
and Ubuntu 18.10. (CVE-2018-15687)
It was discovered that systemd-tmpfiles mishandled symlinks in
non-terminal path components. A local attacker could potentially exploit
this by gaining ownership of certain files to obtain root
Red Hat
systemd: line splitting via fgets() allows for state injection during daemon-reexec
vendor_redhat·2018-10-26·CVSS 7.8
CVE-2018-15686 [HIGH] CWE-20 systemd: line splitting via fgets() allows for state injection during daemon-reexec
systemd: line splitting via fgets() allows for state injection during daemon-reexec
A vulnerability in unit_deserialize of systemd allows an attacker to supply arbitrary state across systemd re-execution via NotifyAccess. This can be used to improperly influence systemd execution and possibly lead to root privilege escalation. Affected releases are systemd versions up to and including 239.
It was discovered that systemd is vulnerable to a state injection attack when deserializing the state of a service. Properties longer than LINE_MAX are not correctly parsed and an attacker may abuse this flaw in particularly configured services to inject, change, or corrupt the service state.
Package: systemd (Red Hat Enterprise Linux 8) - Not affected
Microsoft
systemd: reexec state injection: fgets() on overlong lines leads to line splitting
vendor_msrc·2018-10-09·CVSS 7.8
CVE-2018-15686 [HIGH] CWE-502 systemd: reexec state injection: fgets() on overlong lines leads to line splitting
systemd: reexec state injection: fgets() on overlong lines leads to line splitting
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
canonical: canonical
Customer Action Required: Yes
Remediation: CBL-Mariner
Debian
CVE-2018-15686: systemd - A vulnerability in unit_deserialize of systemd allows an attacker to supply arbi...
vendor_debian·2018·CVSS 7.8
CVE-2018-15686 [HIGH] CVE-2018-15686: systemd - A vulnerability in unit_deserialize of systemd allows an attacker to supply arbi...
A vulnerability in unit_deserialize of systemd allows an attacker to supply arbitrary state across systemd re-execution via NotifyAccess. This can be used to improperly influence systemd execution and possibly lead to root privilege escalation. Affected releases are systemd versions up to and including 239.
Scope: local
bookworm: resolved (fixed in 239-12)
bullseye: resolved (fixed in 239-12)
forky: resolved (fixed in 239-12)
sid: resolved (fixed in 239-12)
trixie: resolved (fixed in 239-12)
GHSA
GHSA-86rx-vp92-xvgg: A vulnerability in unit_deserialize of systemd allows an attacker to supply arbitrary state across systemd re-execution via NotifyAccess
ghsa_unreviewed·2022-05-13
CVE-2018-15686 [HIGH] CWE-502 GHSA-86rx-vp92-xvgg: A vulnerability in unit_deserialize of systemd allows an attacker to supply arbitrary state across systemd re-execution via NotifyAccess
A vulnerability in unit_deserialize of systemd allows an attacker to supply arbitrary state across systemd re-execution via NotifyAccess. This can be used to improperly influence systemd execution and possibly lead to root privilege escalation. Affected releases are systemd versions up to and including 239.
OSV
systemd regression
osv·2018-11-27·CVSS 7.8
CVE-2018-6954 [HIGH] systemd regression
systemd regression
USN-3816-1 fixed vulnerabilities in systemd. The fix for CVE-2018-6954
caused a regression in systemd-tmpfiles when running Ubuntu inside a
container on some older kernels. This issue only affected Ubuntu 16.04
LTS. In order to continue to support this configuration, the fixes for
CVE-2018-6954 have been reverted.
We apologize for the inconvenience.
Original advisory details:
Jann Horn discovered that unit_deserialize incorrectly handled status messages
above a certain length. A local attacker could potentially exploit this via
NotifyAccess to inject arbitrary state across re-execution and obtain root
privileges. (CVE-2018-15686)
Jann Horn discovered a race condition in chown_one(). A local attacker
could potentially exploit this by setting arbitrary permissions on
OSV
systemd vulnerability
osv·2018-11-19·CVSS 7.8
CVE-2018-6954 [HIGH] systemd vulnerability
systemd vulnerability
USN-3816-1 fixed several vulnerabilities in systemd. However, the fix for
CVE-2018-6954 was not sufficient. This update provides the remaining fixes.
We apologize for the inconvenience.
Original advisory details:
Jann Horn discovered that unit_deserialize incorrectly handled status messages
above a certain length. A local attacker could potentially exploit this via
NotifyAccess to inject arbitrary state across re-execution and obtain root
privileges. (CVE-2018-15686)
Jann Horn discovered a race condition in chown_one(). A local attacker
could potentially exploit this by setting arbitrary permissions on certain
files to obtain root privileges. This issue only affected Ubuntu 18.04 LTS
and Ubuntu 18.10. (CVE-2018-15687)
It was discovered that systemd-tmpfiles mish
OSV
systemd vulnerabilities
osv·2018-11-12·CVSS 7.8
CVE-2018-15686 [HIGH] systemd vulnerabilities
systemd vulnerabilities
Jann Horn discovered that unit_deserialize incorrectly handled status messages
above a certain length. A local attacker could potentially exploit this via
NotifyAccess to inject arbitrary state across re-execution and obtain root
privileges. (CVE-2018-15686)
Jann Horn discovered a race condition in chown_one(). A local attacker
could potentially exploit this by setting arbitrary permissions on certain
files to obtain root privileges. This issue only affected Ubuntu 18.04 LTS
and Ubuntu 18.10. (CVE-2018-15687)
It was discovered that systemd-tmpfiles mishandled symlinks in
non-terminal path components. A local attacker could potentially exploit
this by gaining ownership of certain files to obtain root privileges. This
issue only affected Ubuntu 16.04 LTS and Ubuntu
OSV
CVE-2018-15686: A vulnerability in unit_deserialize of systemd allows an attacker to supply arbitrary state across systemd re-execution via NotifyAccess
osv·2018-10-26·CVSS 7.8
CVE-2018-15686 [HIGH] CVE-2018-15686: A vulnerability in unit_deserialize of systemd allows an attacker to supply arbitrary state across systemd re-execution via NotifyAccess
A vulnerability in unit_deserialize of systemd allows an attacker to supply arbitrary state across systemd re-execution via NotifyAccess. This can be used to improperly influence systemd execution and possibly lead to root privilege escalation. Affected releases are systemd versions up to and including 239.
No detection rules found.
Bugzilla
CVE-2018-15686 systemd: Line splitting via fgets() allows for state injection during daemon-reexec [fedora-all]
bugzilla·2018-10-26·CVSS 7.8
CVE-2018-15686 [HIGH] CVE-2018-15686 systemd: Line splitting via fgets() allows for state injection during daemon-reexec [fedora-all]
CVE-2018-15686 systemd: Line splitting via fgets() allows for state injection during daemon-reexec [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue a
Bugzilla
CVE-2018-15686 systemd: line splitting via fgets() allows for state injection during daemon-reexec
bugzilla·2018-10-15·CVSS 7.8
CVE-2018-15686 [HIGH] CVE-2018-15686 systemd: line splitting via fgets() allows for state injection during daemon-reexec
CVE-2018-15686 systemd: line splitting via fgets() allows for state injection during daemon-reexec
systemd is vulnerable to line splitting via long lines read by fgets() in the unit_deserialize() function during daemon-reexec (e.g. during a package upgrade) allowing for state injection. Systemd services with `NotifyAccess != none` and malicious executables can exploit this vulnerability resulting corrupted process state.
Discussion:
When systemd re-executes, the state is serialized and then deserialized after the re-execution. Function unit_deserialize() in file unit.c does not properly handle lines longer than LINE_MAX and the content of a property longer than that is parsed as part of the serialized state, allowing an attacker to corrupt the state of the service (e.g. change the main-
http://www.securityfocus.com/bid/105747https://access.redhat.com/errata/RHSA-2019:2091https://access.redhat.com/errata/RHSA-2019:3222https://access.redhat.com/errata/RHSA-2020:0593https://github.com/systemd/systemd/pull/10519https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2018/11/msg00017.htmlhttps://security.gentoo.org/glsa/201810-10https://usn.ubuntu.com/3816-1/https://www.exploit-db.com/exploits/45714/https://www.oracle.com//security-alerts/cpujul2021.htmlhttp://www.securityfocus.com/bid/105747https://access.redhat.com/errata/RHSA-2019:2091https://access.redhat.com/errata/RHSA-2019:3222https://access.redhat.com/errata/RHSA-2020:0593https://github.com/systemd/systemd/pull/10519https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2018/11/msg00017.htmlhttps://security.gentoo.org/glsa/201810-10https://usn.ubuntu.com/3816-1/https://www.exploit-db.com/exploits/45714/https://www.oracle.com//security-alerts/cpujul2021.html
2018-10-26
Published