cbcvebase.
CVE-2018-15686
published 2018-10-26

CVE-2018-15686: A vulnerability in unit_deserialize of systemd allows an attacker to supply arbitrary state across systemd re-execution via NotifyAccess. This can be used to…

high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EXPLOIT
A vulnerability in unit_deserialize of systemd allows an attacker to supply arbitrary state across systemd re-execution via NotifyAccess. This can be used to improperly influence systemd execution and possibly lead to root privilege escalation. Affected releases are systemd versions up to and including 239.

Affected

20 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiansystemd< systemd 239-12 (bookworm)systemd 239-12 (bookworm)
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccm1_systemd_239-31_on_cbl_mariner_1.0
oraclecommunications_cloud_native_core_network_function_cloud_native_environment
systemdsystemdunspecified – 239
systemd_projectsystemd<= 239
systemd_projectsystemd>= 0 < 239-12239-12
systemd_projectsystemd>= 0 < 239-12239-12
systemd_projectsystemd>= 0 < 239-12239-12
systemd_projectsystemd>= 0 < 239-12239-12
systemd_projectsystemd>= 0 < 229-4ubuntu21.9229-4ubuntu21.9
systemd_projectsystemd>= 0 < 229-4ubuntu21.10229-4ubuntu21.10
systemd_projectsystemd>= 0 < 229-4ubuntu21.8229-4ubuntu21.8
systemd_projectsystemd>= 0 < 237-3ubuntu10.9237-3ubuntu10.9
systemd_projectsystemd>= 0 < 237-3ubuntu10.6237-3ubuntu10.6

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH