CVE-2018-15688
published 2018-10-26CVE-2018-15688: A buffer overflow vulnerability in the dhcp6 client of systemd allows a malicious dhcp6 server to overwrite heap memory in systemd-networkd. Affected releases…
PriorityP347high8.8CVSS 3.1
AVAACLPRNUINSUCHIHAH
EPSS
1.68%
74.5th percentile
A buffer overflow vulnerability in the dhcp6 client of systemd allows a malicious dhcp6 server to overwrite heap memory in systemd-networkd. Affected releases are systemd: versions up to and including 239.
Affected
25 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | network-manager | < network-manager 1.14.4-2 (bookworm) | network-manager 1.14.4-2 (bookworm) |
| debian | systemd | < network-manager 1.14.4-2 (bookworm) | network-manager 1.14.4-2 (bookworm) |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cm1_systemd_239-31_on_cbl_mariner_1.0 | — | — |
| network-manager_project | network-manager | >= 0 < 1.14.4-2 | 1.14.4-2 |
| network-manager_project | network-manager | >= 0 < 1.14.4-2 | 1.14.4-2 |
| network-manager_project | network-manager | >= 0 < 1.14.4-2 | 1.14.4-2 |
| network-manager_project | network-manager | >= 0 < 1.14.4-2 | 1.14.4-2 |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_workstation | — | — |
| systemd | systemd | unspecified – 239 | — |
| systemd_project | systemd | <= 239 | — |
| systemd_project | systemd | >= 0 < 239-11 | 239-11 |
| systemd_project | systemd | >= 0 < 239-11 | 239-11 |
| systemd_project | systemd | >= 0 < 239-11 | 239-11 |
| systemd_project | systemd | >= 0 < 239-11 | 239-11 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv3.08.8HIGHCVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.05.8MEDIUMAV:A/AC:L/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8HIGH
vendor_msrc8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8h24-cwhj-2xgm: A buffer overflow vulnerability in the dhcp6 client of systemd allows a malicious dhcp6 server to overwrite heap memory in systemd-networkd
ghsa_unreviewed·2022-05-13
CVE-2018-15688 [HIGH] CWE-120 GHSA-8h24-cwhj-2xgm: A buffer overflow vulnerability in the dhcp6 client of systemd allows a malicious dhcp6 server to overwrite heap memory in systemd-networkd
A buffer overflow vulnerability in the dhcp6 client of systemd allows a malicious dhcp6 server to overwrite heap memory in systemd-networkd. Affected releases are systemd: versions up to and including 239.
OSV
CVE-2018-15688: A buffer overflow vulnerability in the dhcp6 client of systemd allows a malicious dhcp6 server to overwrite heap memory in systemd-networkd
osv·2018-10-26·CVSS 8.8
CVE-2018-15688 [HIGH] CVE-2018-15688: A buffer overflow vulnerability in the dhcp6 client of systemd allows a malicious dhcp6 server to overwrite heap memory in systemd-networkd
A buffer overflow vulnerability in the dhcp6 client of systemd allows a malicious dhcp6 server to overwrite heap memory in systemd-networkd. Affected releases are systemd: versions up to and including 239.
Ubuntu
systemd vulnerability
vendor_ubuntu·2018-11-05
CVE-2018-15688 systemd vulnerability
Title: systemd vulnerability
Summary: systemd-networkd could be made to crash or run programs if it received
specially crafted network traffic.
Felix Wilhelm discovered that the systemd-networkd DHCPv6 client
incorrectly handled certain DHCPv6 messages. In configurations where
systemd-networkd is being used, an attacker on the same network could use
this issue to cause systemd-networkd to crash, resulting in a denial of
service, or possibly execute arbitrary code.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Ubuntu
NetworkManager vulnerability
vendor_ubuntu·2018-11-05
CVE-2018-15688 NetworkManager vulnerability
Title: NetworkManager vulnerability
Summary: NetworkManager could be made to crash or run programs if it received
specially crafted network traffic.
Felix Wilhelm discovered that the NetworkManager internal DHCPv6 client
incorrectly handled certain DHCPv6 messages. In non-default configurations
where the internal DHCP client is enabled, an attacker on the same network
could use this issue to cause NetworkManager to crash, resulting in a
denial of service, or possibly execute arbitrary code.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Red Hat
systemd: Out-of-bounds heap write in systemd-networkd dhcpv6 option handling
vendor_redhat·2018-10-26·CVSS 8.8
CVE-2018-15688 [HIGH] CWE-131 systemd: Out-of-bounds heap write in systemd-networkd dhcpv6 option handling
systemd: Out-of-bounds heap write in systemd-networkd dhcpv6 option handling
A buffer overflow vulnerability in the dhcp6 client of systemd allows a malicious dhcp6 server to overwrite heap memory in systemd-networkd. Affected releases are systemd: versions up to and including 239.
It was discovered that systemd-network does not correctly keep track of a buffer size when constructing DHCPv6 packets. This flaw may lead to an integer underflow that can be used to produce an heap-based buffer overflow. A malicious host on the same network segment as the victim's one may advertise itself as a DHCPv6 server and exploit this flaw to cause a Denial of Service or potentially gain code execution on the victim's machine.
Statement: This issue affects the versions of systemd-networkd as shipped wi
Microsoft
Out-of-Bounds write in systemd-networkd dhcpv6 option handling
vendor_msrc·2018-10-09·CVSS 8.8
CVE-2018-15688 [HIGH] CWE-120 Out-of-Bounds write in systemd-networkd dhcpv6 option handling
Out-of-Bounds write in systemd-networkd dhcpv6 option handling
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
canonical: canonical
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference
Debian
CVE-2018-15688: network-manager - A buffer overflow vulnerability in the dhcp6 client of systemd allows a maliciou...
vendor_debian·2018·CVSS 8.8
CVE-2018-15688 [HIGH] CVE-2018-15688: network-manager - A buffer overflow vulnerability in the dhcp6 client of systemd allows a maliciou...
A buffer overflow vulnerability in the dhcp6 client of systemd allows a malicious dhcp6 server to overwrite heap memory in systemd-networkd. Affected releases are systemd: versions up to and including 239.
Scope: local
bookworm: resolved (fixed in 1.14.4-2)
bullseye: resolved (fixed in 1.14.4-2)
forky: resolved (fixed in 1.14.4-2)
sid: resolved (fixed in 1.14.4-2)
trixie: resolved (fixed in 1.14.4-2)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-15688 NetworkManager: systemd: Out-of-bounds heap write in systemd-networkd dhcpv6 option handling [fedora-all]
bugzilla·2018-10-29·CVSS 8.8
CVE-2018-15688 [HIGH] CVE-2018-15688 NetworkManager: systemd: Out-of-bounds heap write in systemd-networkd dhcpv6 option handling [fedora-all]
CVE-2018-15688 NetworkManager: systemd: Out-of-bounds heap write in systemd-networkd dhcpv6 option handling [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: thi
Bugzilla
CVE-2018-15688 systemd: Out-of-bounds heap write in systemd-networkd dhcpv6 option handling [fedora-all]
bugzilla·2018-10-26·CVSS 8.8
CVE-2018-15688 [HIGH] CVE-2018-15688 systemd: Out-of-bounds heap write in systemd-networkd dhcpv6 option handling [fedora-all]
CVE-2018-15688 systemd: Out-of-bounds heap write in systemd-networkd dhcpv6 option handling [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects
Bugzilla
CVE-2018-15688 systemd: Out-of-bounds heap write in systemd-networkd dhcpv6 option handling
bugzilla·2018-10-15·CVSS 8.8
CVE-2018-15688 [HIGH] CVE-2018-15688 systemd: Out-of-bounds heap write in systemd-networkd dhcpv6 option handling
CVE-2018-15688 systemd: Out-of-bounds heap write in systemd-networkd dhcpv6 option handling
systemd-networkd is vulnerable to an out out-of-bounds heap write in the DHCPv6 client when handling options sent by network adjacent DHCP servers. A attacker could exploit this via malicious DHCP server to corrupt heap memory on client machines, resulting in a denial of service or potential code execution.
Discussion:
The DHCPv6 client implemented in systemd-networkd does not correctly handle the size of the temporary buffer used to construct the packet that needs to be sent to the DHCPv6 server. In particular dhcp6-option.c:dhcp6_option_append_ia() causes an integer overflow that can be used to write beyond the limits of the temporary buffer.
---
RHEL 7 does not ship systemd-networkd by defau
http://www.securityfocus.com/bid/105745https://access.redhat.com/errata/RHBA-2019:0327https://access.redhat.com/errata/RHSA-2018:3665https://access.redhat.com/errata/RHSA-2019:0049https://github.com/systemd/systemd/pull/10518https://lists.debian.org/debian-lts-announce/2018/11/msg00017.htmlhttps://security.gentoo.org/glsa/201810-10https://usn.ubuntu.com/3806-1/https://usn.ubuntu.com/3807-1/http://www.securityfocus.com/bid/105745https://access.redhat.com/errata/RHBA-2019:0327https://access.redhat.com/errata/RHSA-2018:3665https://access.redhat.com/errata/RHSA-2019:0049https://github.com/systemd/systemd/pull/10518https://lists.debian.org/debian-lts-announce/2018/11/msg00017.htmlhttps://security.gentoo.org/glsa/201810-10https://usn.ubuntu.com/3806-1/https://usn.ubuntu.com/3807-1/
2018-10-26
Published