CVE-2018-16865
published 2019-01-11CVE-2018-16865: An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journald when many…
PriorityP345high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
2.96%
85.6th percentile
An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journald when many entries are sent to the journal socket. A local attacker, or a remote one if systemd-journal-remote is used, may use this flaw to crash systemd-journald or execute code with journald privileges. Versions through v240 are vulnerable.
Affected
31 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | systemd | < systemd 240-4 (bookworm) | systemd 240-4 (bookworm) |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cm1_systemd_239-31_on_cbl_mariner_1.0 | — | — |
| oracle | communications_session_border_controller | — | — |
| oracle | communications_session_border_controller | — | — |
| oracle | communications_session_border_controller | — | — |
| oracle | enterprise_communications_broker | — | — |
| oracle | enterprise_communications_broker | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_workstation | — | — |
| systemd_project | systemd | <= 240 | — |
| systemd_project | systemd | >= 0 < 240-4 | 240-4 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
systemd vulnerabilities
vendor_ubuntu·2019-01-11·CVSS 7.8
CVE-2018-16864 [HIGH] systemd vulnerabilities
Title: systemd vulnerabilities
Summary: Several security issues were fixed in systemd.
It was discovered that systemd-journald allocated variable-length buffers
for certain message fields on the stack. A local attacker could
potentially exploit this to cause a denial of service, or execute
arbitrary code. (CVE-2018-16864)
It was discovered that systemd-journald allocated variable-length arrays
of objects representing message fields on the stack. A local attacker
could potentially exploit this to cause a denial of service, or execute
arbitrary code. (CVE-2018-16865)
An out-of-bounds read was discovered in systemd-journald. A local
attacker could potentially exploit this to obtain sensitive information
and bypass ASLR protections. (CVE-2018-16866)
Instructions: After a standard system u
Red Hat
systemd: stack overflow when receiving many journald entries
vendor_redhat·2019-01-09·CVSS 7.8
CVE-2018-16865 [HIGH] CWE-770 systemd: stack overflow when receiving many journald entries
systemd: stack overflow when receiving many journald entries
An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journald when many entries are sent to the journal socket. A local attacker, or a remote one if systemd-journal-remote is used, may use this flaw to crash systemd-journald or execute code with journald privileges. Versions through v240 are vulnerable.
An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journald when many entries are sent to the journal socket. A local attacker, or a remote one if systemd-journal-remote is used, may use this flaw to crash systemd-journald or execute code with journald privileges.
St
Microsoft
An allocation of memory without limits that could result in the stack clashing with another memory region was discovered in systemd-journald when many entries are sent to the journal socket. A local a
vendor_msrc·2019-01-08·CVSS 7.8
CVE-2018-16865 [HIGH] CWE-770 An allocation of memory without limits that could result in the stack clashing with another memory region was discovered in systemd-journald when many entries are sent to the journal socket. A local a
An allocation of memory without limits that could result in the stack clashing with another memory region was discovered in systemd-journald when many entries are sent to the journal socket. A local attacker or a remote one if systemd-journal-remote is used may use this flaw to crash systemd-journald or execute code with journald privileges. Versions through v240 are vulnerable.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparenc
Debian
CVE-2018-16865: systemd - An allocation of memory without limits, that could result in the stack clashing ...
vendor_debian·2018·CVSS 7.8
CVE-2018-16865 [HIGH] CVE-2018-16865: systemd - An allocation of memory without limits, that could result in the stack clashing ...
An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journald when many entries are sent to the journal socket. A local attacker, or a remote one if systemd-journal-remote is used, may use this flaw to crash systemd-journald or execute code with journald privileges. Versions through v240 are vulnerable.
Scope: local
bookworm: resolved (fixed in 240-4)
bullseye: resolved (fixed in 240-4)
forky: resolved (fixed in 240-4)
sid: resolved (fixed in 240-4)
trixie: resolved (fixed in 240-4)
GHSA
GHSA-cwf3-gffj-25fm: An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journald when ma
ghsa_unreviewed·2022-05-13
CVE-2018-16865 [HIGH] CWE-770 GHSA-cwf3-gffj-25fm: An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journald when ma
An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journald when many entries are sent to the journal socket. A local attacker, or a remote one if systemd-journal-remote is used, may use this flaw to crash systemd-journald or execute code with journald privileges. Versions through v240 are vulnerable.
OSV
systemd vulnerabilities
osv·2019-01-11·CVSS 7.8
CVE-2018-16864 [HIGH] systemd vulnerabilities
systemd vulnerabilities
It was discovered that systemd-journald allocated variable-length buffers
for certain message fields on the stack. A local attacker could
potentially exploit this to cause a denial of service, or execute
arbitrary code. (CVE-2018-16864)
It was discovered that systemd-journald allocated variable-length arrays
of objects representing message fields on the stack. A local attacker
could potentially exploit this to cause a denial of service, or execute
arbitrary code. (CVE-2018-16865)
An out-of-bounds read was discovered in systemd-journald. A local
attacker could potentially exploit this to obtain sensitive information
and bypass ASLR protections. (CVE-2018-16866)
OSV
CVE-2018-16865: An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journald when ma
osv·2019-01-11·CVSS 7.8
CVE-2018-16865 [HIGH] CVE-2018-16865: An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journald when ma
An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journald when many entries are sent to the journal socket. A local attacker, or a remote one if systemd-journal-remote is used, may use this flaw to crash systemd-journald or execute code with journald privileges. Versions through v240 are vulnerable.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-16865 systemd: stack overflow when receiving many journald entries [fedora-all]
bugzilla·2019-01-10·CVSS 7.8
CVE-2018-16865 [HIGH] CVE-2018-16865 systemd: stack overflow when receiving many journald entries [fedora-all]
CVE-2018-16865 systemd: stack overflow when receiving many journald entries [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple support
Bugzilla
CVE-2018-16865 systemd: stack overflow when receiving many journald entries
bugzilla·2018-11-27·CVSS 7.8
CVE-2018-16865 [HIGH] CVE-2018-16865 systemd: stack overflow when receiving many journald entries
CVE-2018-16865 systemd: stack overflow when receiving many journald entries
A flaw was found in systemd-journald. An uncontrolled alloca() by writing a crafted message to /run/systemd/journal/socket that results in a stack buffer overflow. This can lead to a denial of service attack or arbitrary code execution in some cases.
Discussion:
The exploit described by reporter is a stack clash: since crafted input can cause a maximum alloca() of 4GiB (which may not be entirely written to) it is possible to jump over the guard page if the randomized offset between the stack and the next writeable segment on the heap is smaller than this.
This is claimed to occur approx 1/2048 of the time. Testing on rhel-7 bears this out approximately. The rest of the time, this attack will be harmless (and no
http://packetstormsecurity.com/files/152841/System-Down-A-systemd-journald-Exploit.htmlhttp://seclists.org/fulldisclosure/2019/May/21http://www.openwall.com/lists/oss-security/2019/05/10/4http://www.openwall.com/lists/oss-security/2021/07/20/2http://www.securityfocus.com/bid/106525https://access.redhat.com/errata/RHBA-2019:0327https://access.redhat.com/errata/RHSA-2019:0049https://access.redhat.com/errata/RHSA-2019:0204https://access.redhat.com/errata/RHSA-2019:0271https://access.redhat.com/errata/RHSA-2019:0342https://access.redhat.com/errata/RHSA-2019:0361https://access.redhat.com/errata/RHSA-2019:2402https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16865https://lists.debian.org/debian-lts-announce/2019/01/msg00016.htmlhttps://seclists.org/bugtraq/2019/May/25https://security.gentoo.org/glsa/201903-07https://security.netapp.com/advisory/ntap-20190117-0001/https://usn.ubuntu.com/3855-1/https://www.debian.org/security/2019/dsa-4367https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.htmlhttps://www.qualys.com/2019/01/09/system-down/system-down.txthttp://packetstormsecurity.com/files/152841/System-Down-A-systemd-journald-Exploit.htmlhttp://seclists.org/fulldisclosure/2019/May/21http://www.openwall.com/lists/oss-security/2019/05/10/4http://www.openwall.com/lists/oss-security/2021/07/20/2http://www.securityfocus.com/bid/106525https://access.redhat.com/errata/RHBA-2019:0327https://access.redhat.com/errata/RHSA-2019:0049https://access.redhat.com/errata/RHSA-2019:0204https://access.redhat.com/errata/RHSA-2019:0271https://access.redhat.com/errata/RHSA-2019:0342https://access.redhat.com/errata/RHSA-2019:0361https://access.redhat.com/errata/RHSA-2019:2402https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16865https://lists.debian.org/debian-lts-announce/2019/01/msg00016.htmlhttps://seclists.org/bugtraq/2019/May/25https://security.gentoo.org/glsa/201903-07https://security.netapp.com/advisory/ntap-20190117-0001/https://usn.ubuntu.com/3855-1/https://www.debian.org/security/2019/dsa-4367https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.htmlhttps://www.qualys.com/2019/01/09/system-down/system-down.txt
2019-01-11
Published