Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2019-3844

CWE-26812 documents10 sources
Severity
7.8HIGH
EPSS
0.2%
top 64.28%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedApr 26
Latest updateMay 24

Description

It was discovered that a systemd service that uses DynamicUser property can get new privileges through the execution of SUID binaries, which would allow to create binaries owned by the service transient group with the setgid bit set. A local attacker may use this flaw to access resources that will be owned by a potentially different service in the future, when the GID will be recycled.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages3 packages

Debiansystemd< 242-4+3

Also affects: Ubuntu Linux 16.04, 18.04, 19.10

Patches

🔴Vulnerability Details

4
GHSA
GHSA-h647-28xp-2hc8: It was discovered that a systemd service that uses DynamicUser property can get new privileges through the execution of SUID binaries, which would all2022-05-24
OSV
systemd vulnerabilities2020-02-05
OSV
CVE-2019-3844: It was discovered that a systemd service that uses DynamicUser property can get new privileges through the execution of SUID binaries, which would all2019-04-26
CVEList
CVE-2019-3844: It was discovered that a systemd service that uses DynamicUser property can get new privileges through the execution of SUID binaries, which would all2019-04-26

💥Exploits & PoCs

1
Exploit-DB
systemd - DynamicUser can Create setuid Binaries when Assisted by Another Process2019-04-26

📋Vendor Advisories

4
Ubuntu
systemd vulnerabilities2020-02-05
Red Hat
systemd: services with DynamicUser can get new privileges and create SGID binaries2019-04-25
Microsoft
It was discovered that a systemd service that uses DynamicUser property can get new privileges through the execution of SUID binaries which would allow to create binaries owned by the service transien2019-04-09
Debian
CVE-2019-3844: systemd - It was discovered that a systemd service that uses DynamicUser property can get ...2019

💬Community

2
Bugzilla
CVE-2019-3844 systemd: services with DynamicUser can get new privileges and create SGID binaries [fedora-all]2019-04-26
Bugzilla
CVE-2019-3844 systemd: services with DynamicUser can get new privileges and create SGID binaries2019-03-01
CVE-2019-3844 (HIGH CVSS 7.8) | It was discovered that a systemd se | cvebase.io