cbcvebase.
CVE-2018-6954
published 2018-02-13

CVE-2018-6954: systemd-tmpfiles in systemd through 237 mishandles symlinks present in non-terminal path components, which allows local users to obtain ownership of arbitrary…

high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
systemd-tmpfiles in systemd through 237 mishandles symlinks present in non-terminal path components, which allows local users to obtain ownership of arbitrary files via vectors involving creation of a directory and a file under that directory, and later replacing that directory with a symlink. This occurs even if the fs.protected_symlinks sysctl is turned on.

Affected

15 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiansystemd< systemd 238-1 (bookworm)systemd 238-1 (bookworm)
opensuseleap
systemd_projectsystemd<= 237
systemd_projectsystemd>= 0 < 238-1238-1
systemd_projectsystemd>= 0 < 238-1238-1
systemd_projectsystemd>= 0 < 238-1238-1
systemd_projectsystemd>= 0 < 238-1238-1
systemd_projectsystemd>= 0 < 229-4ubuntu21.9229-4ubuntu21.9
systemd_projectsystemd>= 0 < 229-4ubuntu21.10229-4ubuntu21.10
systemd_projectsystemd>= 0 < 229-4ubuntu21.8229-4ubuntu21.8
systemd_projectsystemd>= 0 < 237-3ubuntu10.9237-3ubuntu10.9
systemd_projectsystemd>= 0 < 237-3ubuntu10.6237-3ubuntu10.6

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH