Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2019-3843

Severity
7.8HIGH
EPSS
0.1%
top 68.89%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedApr 26
Latest updateMay 24

Description

It was discovered that a systemd service that uses DynamicUser property can create a SUID/SGID binary that would be allowed to run as the transient service UID/GID even after the service is terminated. A local attacker may use this flaw to access resources that will be owned by a potentially different service in the future, when the UID/GID will be recycled.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages3 packages

Debiansystemd< 242-4+3

Also affects: Fedora 30, Ubuntu Linux 16.04, 18.04, 19.10

Patches

🔴Vulnerability Details

4
GHSA
GHSA-54p3-x8px-4jp3: It was discovered that a systemd service that uses DynamicUser property can create a SUID/SGID binary that would be allowed to run as the transient se2022-05-24
OSV
systemd vulnerabilities2020-02-05
CVEList
CVE-2019-3843: It was discovered that a systemd service that uses DynamicUser property can create a SUID/SGID binary that would be allowed to run as the transient se2019-04-26
OSV
CVE-2019-3843: It was discovered that a systemd service that uses DynamicUser property can create a SUID/SGID binary that would be allowed to run as the transient se2019-04-26

💥Exploits & PoCs

1
Exploit-DB
systemd - DynamicUser can Create setuid Binaries when Assisted by Another Process2019-04-26

📋Vendor Advisories

4
Ubuntu
systemd vulnerabilities2020-02-05
Red Hat
systemd: services with DynamicUser can create SUID/SGID binaries2019-04-25
Microsoft
It was discovered that a systemd service that uses DynamicUser property can create a SUID/SGID binary that would be allowed to run as the transient service UID/GID even after the service is terminated2019-04-09
Debian
CVE-2019-3843: systemd - It was discovered that a systemd service that uses DynamicUser property can crea...2019

💬Community

2
Bugzilla
CVE-2019-3843 systemd: services with DynamicUser can create SUID/SGID binaries [fedora-all]2019-04-26
Bugzilla
CVE-2019-3843 systemd: services with DynamicUser can create SUID/SGID binaries2019-03-01
CVE-2019-3843 (HIGH CVSS 7.8) | It was discovered that a systemd se | cvebase.io