cbcvebase.
CVE-2019-3843
published 2019-04-26

CVE-2019-3843: It was discovered that a systemd service that uses DynamicUser property can create a SUID/SGID binary that would be allowed to run as the transient service…

high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EXPLOIT
It was discovered that a systemd service that uses DynamicUser property can create a SUID/SGID binary that would be allowed to run as the transient service UID/GID even after the service is terminated. A local attacker may use this flaw to access resources that will be owned by a potentially different service in the future, when the UID/GID will be recycled.

Affected

15 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiansystemd< systemd 242-4 (bookworm)systemd 242-4 (bookworm)
fedoraprojectfedora
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccm1_systemd_239-34_on_cbl_mariner_1.0
systemd_projectsystemd< 242242
systemd_projectsystemd>= 0 < 242-4242-4
systemd_projectsystemd>= 0 < 242-4242-4
systemd_projectsystemd>= 0 < 242-4242-4
systemd_projectsystemd>= 0 < 242-4242-4
systemd_projectsystemd>= 0 < 229-4ubuntu21.27229-4ubuntu21.27
systemd_projectsystemd>= 0 < 237-3ubuntu10.38237-3ubuntu10.38

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH