CVE-2019-6454
published 2019-03-21CVE-2019-6454: An issue was discovered in sd-bus in systemd 239. bus_process_object() in libsystemd/sd-bus/bus-objects.c allocates a variable-length stack buffer for…
PriorityP424medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
2.04%
78.9th percentile
An issue was discovered in sd-bus in systemd 239. bus_process_object() in libsystemd/sd-bus/bus-objects.c allocates a variable-length stack buffer for temporarily storing the object path of incoming D-Bus messages. An unprivileged local user can exploit this by sending a specially crafted message to PID1, causing the stack pointer to jump over the stack guard pages into an unmapped memory region and trigger a denial of service (systemd PID1 crash and kernel panic).
Affected
63 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | systemd | < systemd 240-6 (bookworm) | systemd 240-6 (bookworm) |
| fedoraproject | fedora | — | — |
| chrome_chrome | — | — | |
| mcafee | web_gateway | < 7.7.2.21 | 7.7.2.21 |
| mcafee | web_gateway | >= 7.8.0 < 7.8.2.8 | 7.8.2.8 |
| mcafee | web_gateway | >= 8.0.0 < 8.1.1 | 8.1.1 |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cm1_systemd_239-34_on_cbl_mariner_1.0 | — | — |
| opensuse | leap | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_compute_node_eus | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_for_ibm_z_systems_eus | — | — |
| redhat | enterprise_linux_for_ibm_z_systems_eus | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8h89-jj6w-g26p: An issue was discovered in sd-bus in systemd 239
ghsa_unreviewed·2022-05-13
CVE-2019-6454 [MEDIUM] CWE-787 GHSA-8h89-jj6w-g26p: An issue was discovered in sd-bus in systemd 239
An issue was discovered in sd-bus in systemd 239. bus_process_object() in libsystemd/sd-bus/bus-objects.c allocates a variable-length stack buffer for temporarily storing the object path of incoming D-Bus messages. An unprivileged local user can exploit this by sending a specially crafted message to PID1, causing the stack pointer to jump over the stack guard pages into an unmapped memory region and trigger a denial of service (systemd PID1 crash and kernel panic).
OSV
CVE-2019-6454: An issue was discovered in sd-bus in systemd 239
osv·2019-03-21·CVSS 5.5
CVE-2019-6454 [MEDIUM] CVE-2019-6454: An issue was discovered in sd-bus in systemd 239
An issue was discovered in sd-bus in systemd 239. bus_process_object() in libsystemd/sd-bus/bus-objects.c allocates a variable-length stack buffer for temporarily storing the object path of incoming D-Bus messages. An unprivileged local user can exploit this by sending a specially crafted message to PID1, causing the stack pointer to jump over the stack guard pages into an unmapped memory region and trigger a denial of service (systemd PID1 crash and kernel panic).
Chrome
Stable Channel Update for Desktop: CVE-2020-6454
vendor_chrome·2020-04-07·CVSS 8.8
CVE-2020-6454 [HIGH] Stable Channel Update for Desktop: CVE-2020-6454
Stable Channel Update for Desktop
CVE-2020-6454: Use after free in extensions. Reported by Leecraso and Guang Gong of Alpha Lab, Qihoo 360 on 2019-10-29
[$5000][ 1043446 ] High CVE-2020-6423: Use after free in audio
Reported by Anonymous on 2020-01-18
Severity: high
Microsoft
An issue was discovered in sd-bus in systemd 239. bus_process_object() in libsystemd/sd-bus/bus-objects.c allocates a variable-length stack buffer for temporarily storing the object path of incoming D
vendor_msrc·2019-03-12·CVSS 5.5
CVE-2019-6454 [MEDIUM] CWE-787 An issue was discovered in sd-bus in systemd 239. bus_process_object() in libsystemd/sd-bus/bus-objects.c allocates a variable-length stack buffer for temporarily storing the object path of incoming D
An issue was discovered in sd-bus in systemd 239. bus_process_object() in libsystemd/sd-bus/bus-objects.c allocates a variable-length stack buffer for temporarily storing the object path of incoming D-Bus messages. An unprivileged local user can exploit this by sending a specially crafted message to PID1 causing the stack pointer to jump over the stack guard pages into an unmapped memory region and trigger a denial of service (systemd PID1 crash and kernel panic).
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open so
Red Hat
systemd: Insufficient input validation in bus_process_object() resulting in PID 1 crash
vendor_redhat·2019-02-18·CVSS 5.5
CVE-2019-6454 [MEDIUM] CWE-20 systemd: Insufficient input validation in bus_process_object() resulting in PID 1 crash
systemd: Insufficient input validation in bus_process_object() resulting in PID 1 crash
An issue was discovered in sd-bus in systemd 239. bus_process_object() in libsystemd/sd-bus/bus-objects.c allocates a variable-length stack buffer for temporarily storing the object path of incoming D-Bus messages. An unprivileged local user can exploit this by sending a specially crafted message to PID1, causing the stack pointer to jump over the stack guard pages into an unmapped memory region and trigger a denial of service (systemd PID1 crash and kernel panic).
It was discovered that systemd allocates a buffer large enough to store the path field of a dbus message without performing enough checks. A local attacker may trigger this flaw by sending a dbus message to systemd with a large path making
Ubuntu
systemd vulnerability
vendor_ubuntu·2019-02-18
CVE-2019-6454 systemd vulnerability
Title: systemd vulnerability
Summary: systemd could be made to crash if it received specially a crafted
D-Bus message.
It was discovered that systemd incorrectly handled certain D-Bus messages.
A local unprivileged attacker could exploit this in order to crash the
init process, resulting in a system denial-of-service (kernel panic).
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Debian
CVE-2019-6454: systemd - An issue was discovered in sd-bus in systemd 239. bus_process_object() in libsys...
vendor_debian·2019·CVSS 5.5
CVE-2019-6454 [MEDIUM] CVE-2019-6454: systemd - An issue was discovered in sd-bus in systemd 239. bus_process_object() in libsys...
An issue was discovered in sd-bus in systemd 239. bus_process_object() in libsystemd/sd-bus/bus-objects.c allocates a variable-length stack buffer for temporarily storing the object path of incoming D-Bus messages. An unprivileged local user can exploit this by sending a specially crafted message to PID1, causing the stack pointer to jump over the stack guard pages into an unmapped memory region and trigger a denial of service (systemd PID1 crash and kernel panic).
Scope: local
bookworm: resolved (fixed in 240-6)
bullseye: resolved (fixed in 240-6)
forky: resolved (fixed in 240-6)
sid: resolved (fixed in 240-6)
trixie: resolved (fixed in 240-6)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-6454 systemd: Insufficient input validation in bus_process_object() resulting in PID 1 crash [fedora-all]
bugzilla·2019-02-18·CVSS 5.5
CVE-2019-6454 [MEDIUM] CVE-2019-6454 systemd: Insufficient input validation in bus_process_object() resulting in PID 1 crash [fedora-all]
CVE-2019-6454 systemd: Insufficient input validation in bus_process_object() resulting in PID 1 crash [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issu
Bugzilla
CVE-2019-6454 systemd: Insufficient input validation in bus_process_object() resulting in PID 1 crash
bugzilla·2019-01-17·CVSS 5.5
CVE-2019-6454 [MEDIUM] CVE-2019-6454 systemd: Insufficient input validation in bus_process_object() resulting in PID 1 crash
CVE-2019-6454 systemd: Insufficient input validation in bus_process_object() resulting in PID 1 crash
It was found that bus_process_object() in bus-objects.c allocates a buffer on the stack large enough to temporarily store the object path specified in the incoming message. A malicious unprivileged local user to send a message which results in the stack pointer moving outside of the bounds of the currently mapped stack region, jumping over the stack guard pages. A specifically crafted DBUS nessage could crash PID 1 and result in a subsequent kernel panic.
Discussion:
systemd tries to setup a signal handler to intercept segmentation faults and spawn a shell in case of crashes, however due to the nature of the flaw, the kernel is not able to call the handler and it just makes PID 1 crash
http://lists.opensuse.org/opensuse-security-announce/2019-02/msg00070.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-05/msg00062.htmlhttp://www.openwall.com/lists/oss-security/2019/02/18/3http://www.openwall.com/lists/oss-security/2019/02/19/1http://www.openwall.com/lists/oss-security/2021/07/20/2http://www.securityfocus.com/bid/107081https://access.redhat.com/errata/RHSA-2019:0368https://access.redhat.com/errata/RHSA-2019:0990https://access.redhat.com/errata/RHSA-2019:1322https://access.redhat.com/errata/RHSA-2019:1502https://access.redhat.com/errata/RHSA-2019:2805https://github.com/systemd/systemd/commits/master/src/libsystemd/sd-bus/bus-objects.chttps://kc.mcafee.com/corporate/index?page=content&id=SB10278https://lists.debian.org/debian-lts-announce/2019/02/msg00031.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N67IOBOTDOMVNQJ5QRU2MXLEECXPGNVJ/https://security.netapp.com/advisory/ntap-20190327-0004/https://usn.ubuntu.com/3891-1/https://www.debian.org/security/2019/dsa-4393http://lists.opensuse.org/opensuse-security-announce/2019-02/msg00070.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-05/msg00062.htmlhttp://www.openwall.com/lists/oss-security/2019/02/18/3http://www.openwall.com/lists/oss-security/2019/02/19/1http://www.openwall.com/lists/oss-security/2021/07/20/2http://www.securityfocus.com/bid/107081https://access.redhat.com/errata/RHSA-2019:0368https://access.redhat.com/errata/RHSA-2019:0990https://access.redhat.com/errata/RHSA-2019:1322https://access.redhat.com/errata/RHSA-2019:1502https://access.redhat.com/errata/RHSA-2019:2805https://github.com/systemd/systemd/commits/master/src/libsystemd/sd-bus/bus-objects.chttps://kc.mcafee.com/corporate/index?page=content&id=SB10278https://lists.debian.org/debian-lts-announce/2019/02/msg00031.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N67IOBOTDOMVNQJ5QRU2MXLEECXPGNVJ/https://security.netapp.com/advisory/ntap-20190327-0004/https://usn.ubuntu.com/3891-1/https://www.debian.org/security/2019/dsa-4393
2019-03-21
Published