CVE-2018-16864
published 2019-01-28CVE-2018-16864: A memory leak was discovered in the backport of fixes for CVE-2018-16864 in Red Hat Enterprise Linux. Function dispatch_message_real() in journald-server.c…
PriorityP340high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.72%
49.6th percentile
A memory leak was discovered in the backport of fixes for CVE-2018-16864 in Red Hat Enterprise Linux. Function dispatch_message_real() in journald-server.c does not free the memory allocated by set_iovec_field_free() to store the `_CMDLINE=` entry. A local attacker may use this flaw to make systemd-journald crash. This issue only affects versions shipped with Red Hat Enterprise since v219-62.2.
Affected
36 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | systemd | < systemd 240-4 (bookworm) | systemd 240-4 (bookworm) |
| debian | systemd | — | — |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cm1_systemd_239-31_on_cbl_mariner_1.0 | — | — |
| oracle | communications_session_border_controller | — | — |
| oracle | communications_session_border_controller | — | — |
| oracle | communications_session_border_controller | — | — |
| oracle | enterprise_communications_broker | — | — |
| oracle | enterprise_communications_broker | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv3.07.4HIGHCVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-c7jw-qwf7-gqxx: A memory leak was discovered in the backport of fixes for CVE-2018-16864 in Red Hat Enterprise Linux
ghsa_unreviewed·2022-05-13·CVSS 7.8
CVE-2019-3815 [HIGH] CWE-401 GHSA-c7jw-qwf7-gqxx: A memory leak was discovered in the backport of fixes for CVE-2018-16864 in Red Hat Enterprise Linux
A memory leak was discovered in the backport of fixes for CVE-2018-16864 in Red Hat Enterprise Linux. Function dispatch_message_real() in journald-server.c does not free the memory allocated by set_iovec_field_free() to store the `_CMDLINE=` entry. A local attacker may use this flaw to make systemd-journald crash. This issue only affects versions shipped with Red Hat Enterprise since v219-62.2.
GHSA
GHSA-h53q-m6g5-wfq9: An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journald when a
ghsa_unreviewed·2022-05-13
CVE-2018-16864 [HIGH] CWE-770 GHSA-h53q-m6g5-wfq9: An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journald when a
An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journald when a program with long command line arguments calls syslog. A local attacker may use this flaw to crash systemd-journald or escalate his privileges. Versions through v240 are vulnerable.
OSV
systemd vulnerabilities
osv·2019-01-11·CVSS 7.8
CVE-2018-16864 [HIGH] systemd vulnerabilities
systemd vulnerabilities
It was discovered that systemd-journald allocated variable-length buffers
for certain message fields on the stack. A local attacker could
potentially exploit this to cause a denial of service, or execute
arbitrary code. (CVE-2018-16864)
It was discovered that systemd-journald allocated variable-length arrays
of objects representing message fields on the stack. A local attacker
could potentially exploit this to cause a denial of service, or execute
arbitrary code. (CVE-2018-16865)
An out-of-bounds read was discovered in systemd-journald. A local
attacker could potentially exploit this to obtain sensitive information
and bypass ASLR protections. (CVE-2018-16866)
OSV
CVE-2018-16864: An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journald when a
osv·2019-01-11·CVSS 7.8
CVE-2018-16864 [HIGH] CVE-2018-16864: An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journald when a
An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journald when a program with long command line arguments calls syslog. A local attacker may use this flaw to crash systemd-journald or escalate his privileges. Versions through v240 are vulnerable.
Red Hat
systemd: memory leak in journald-server.c introduced by fix for CVE-2018-16864
vendor_redhat·2019-01-14·CVSS 7.8
CVE-2019-3815 [HIGH] CWE-401 systemd: memory leak in journald-server.c introduced by fix for CVE-2018-16864
systemd: memory leak in journald-server.c introduced by fix for CVE-2018-16864
A memory leak was discovered in the backport of fixes for CVE-2018-16864 in Red Hat Enterprise Linux. Function dispatch_message_real() in journald-server.c does not free the memory allocated by set_iovec_field_free() to store the `_CMDLINE=` entry. A local attacker may use this flaw to make systemd-journald crash. This issue only affects versions shipped with Red Hat Enterprise since v219-62.2.
A memory leak was discovered in the backport of fixes for CVE-2018-16864 in Red Hat Enterprise Linux. Function dispatch_message_real() in journald-server.c does not free the memory allocated by set_iovec_field_free() to store the `_CMDLINE=` entry. A local attacker may use this flaw to make systemd-journald crash.
Stat
Ubuntu
systemd vulnerabilities
vendor_ubuntu·2019-01-11·CVSS 7.8
CVE-2018-16864 [HIGH] systemd vulnerabilities
Title: systemd vulnerabilities
Summary: Several security issues were fixed in systemd.
It was discovered that systemd-journald allocated variable-length buffers
for certain message fields on the stack. A local attacker could
potentially exploit this to cause a denial of service, or execute
arbitrary code. (CVE-2018-16864)
It was discovered that systemd-journald allocated variable-length arrays
of objects representing message fields on the stack. A local attacker
could potentially exploit this to cause a denial of service, or execute
arbitrary code. (CVE-2018-16865)
An out-of-bounds read was discovered in systemd-journald. A local
attacker could potentially exploit this to obtain sensitive information
and bypass ASLR protections. (CVE-2018-16866)
Instructions: After a standard system u
Red Hat
systemd: stack overflow when calling syslog from a command with long cmdline
vendor_redhat·2019-01-09·CVSS 7.8
CVE-2018-16864 [HIGH] CWE-770 systemd: stack overflow when calling syslog from a command with long cmdline
systemd: stack overflow when calling syslog from a command with long cmdline
An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journald when a program with long command line arguments calls syslog. A local attacker may use this flaw to crash systemd-journald or escalate his privileges. Versions through v240 are vulnerable.
An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journald when a program with long command line arguments calls syslog. A local attacker may use this flaw to crash systemd-journald or escalate privileges.
Statement: This issue affects the versions of systemd as shipped with Red Hat Enterprise Linux 7.
Microsoft
An allocation of memory without limits that could result in the stack clashing with another memory region was discovered in systemd-journald when a program with long command line arguments calls syslo
vendor_msrc·2019-01-08·CVSS 7.8
CVE-2018-16864 [HIGH] CWE-770 An allocation of memory without limits that could result in the stack clashing with another memory region was discovered in systemd-journald when a program with long command line arguments calls syslo
An allocation of memory without limits that could result in the stack clashing with another memory region was discovered in systemd-journald when a program with long command line arguments calls syslog. A local attacker may use this flaw to crash systemd-journald or escalate his privileges. Versions through v240 are vulnerable.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF
Debian
CVE-2019-3815: systemd - A memory leak was discovered in the backport of fixes for CVE-2018-16864 in Red ...
vendor_debian·2019·CVSS 7.8
CVE-2019-3815 [HIGH] CVE-2019-3815: systemd - A memory leak was discovered in the backport of fixes for CVE-2018-16864 in Red ...
A memory leak was discovered in the backport of fixes for CVE-2018-16864 in Red Hat Enterprise Linux. Function dispatch_message_real() in journald-server.c does not free the memory allocated by set_iovec_field_free() to store the `_CMDLINE=` entry. A local attacker may use this flaw to make systemd-journald crash. This issue only affects versions shipped with Red Hat Enterprise since v219-62.2.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
Debian
CVE-2018-16864: systemd - An allocation of memory without limits, that could result in the stack clashing ...
vendor_debian·2018·CVSS 7.8
CVE-2018-16864 [HIGH] CVE-2018-16864: systemd - An allocation of memory without limits, that could result in the stack clashing ...
An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journald when a program with long command line arguments calls syslog. A local attacker may use this flaw to crash systemd-journald or escalate his privileges. Versions through v240 are vulnerable.
Scope: local
bookworm: resolved (fixed in 240-4)
bullseye: resolved (fixed in 240-4)
forky: resolved (fixed in 240-4)
sid: resolved (fixed in 240-4)
trixie: resolved (fixed in 240-4)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-3815 systemd: memory leak in journald-server.c introduced by fix for CVE-2018-16864
bugzilla·2019-01-16·CVSS 7.8
CVE-2019-3815 [HIGH] CVE-2019-3815 systemd: memory leak in journald-server.c introduced by fix for CVE-2018-16864
CVE-2019-3815 systemd: memory leak in journald-server.c introduced by fix for CVE-2018-16864
A memory leak was discovered in the backport of fixes for CVE-2018-16864 in Red Hat Enterprise Linux (since version v219-62.2) and CentOS. Function dispatch_message_real() in journald-server.c does not free the memory allocated by set_iovec_field_free() to store the `_CMDLINE=` entry. A local attacker may use this flaw to make systemd-journald crash.
However systemd-journald crash is automatically restarted by systemd by default.
Discussion:
Statement:
This issue affects version 219-62 of systemd as shipped with Red Hat Enterprise Linux 7.
---
Hi,
Is there any timeline on when this issue will be fixed in RHEL 7.6? This bug is causing journald (and rsyslog) to eat lots of RAM, resulting in s
Bugzilla
CVE-2018-16864 systemd: stack overflow when calling syslog from a command with long cmdline [fedora-all]
bugzilla·2019-01-10·CVSS 7.8
CVE-2018-16864 [HIGH] CVE-2018-16864 systemd: stack overflow when calling syslog from a command with long cmdline [fedora-all]
CVE-2018-16864 systemd: stack overflow when calling syslog from a command with long cmdline [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects
Bugzilla
CVE-2018-16864 systemd: stack overflow when calling syslog from a command with long cmdline
bugzilla·2018-11-27·CVSS 7.8
CVE-2018-16864 [HIGH] CVE-2018-16864 systemd: stack overflow when calling syslog from a command with long cmdline
CVE-2018-16864 systemd: stack overflow when calling syslog from a command with long cmdline
A flaw was found in systemd-journald. A stack buffer overflow when passing several MB of arguments to a program calling syslog function. This can lead to a denial of service attack or arbitrary code execution in some cases.
Discussion:
This boils down to a large alloca(), making it possible to jump the stack pointer into the heap and corrupt the heap region (a "Stack Clash" attack). Since the alloca()ed region is completely written, this will eventually lead to a crash.
The reporters describe achieving code execution by combining the attack with a thread race inside journald, with careful timing they are able to attack the stack of a neighbouring thread which will return to the attacker's pointe
http://www.securityfocus.com/bid/106632https://access.redhat.com/errata/RHBA-2019:0327https://access.redhat.com/errata/RHSA-2019:0201https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3815https://lists.debian.org/debian-lts-announce/2019/03/msg00013.htmlhttp://www.securityfocus.com/bid/106632https://access.redhat.com/errata/RHBA-2019:0327https://access.redhat.com/errata/RHSA-2019:0201https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3815https://lists.debian.org/debian-lts-announce/2019/03/msg00013.html
2019-01-28
Published