cbcvebase.
CVE-2019-6454
published 2019-03-21

CVE-2019-6454: An issue was discovered in sd-bus in systemd 239. bus_process_object() in libsystemd/sd-bus/bus-objects.c allocates a variable-length stack buffer for…

medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
An issue was discovered in sd-bus in systemd 239. bus_process_object() in libsystemd/sd-bus/bus-objects.c allocates a variable-length stack buffer for temporarily storing the object path of incoming D-Bus messages. An unprivileged local user can exploit this by sending a specially crafted message to PID1, causing the stack pointer to jump over the stack guard pages into an unmapped memory region and trigger a denial of service (systemd PID1 crash and kernel panic).

Affected

63 ranges· showing 25
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiandebian_linux
debiansystemd< systemd 240-6 (bookworm)systemd 240-6 (bookworm)
fedoraprojectfedora
googlechrome_chrome
mcafeeweb_gateway< 7.7.2.217.7.2.21
mcafeeweb_gateway>= 7.8.0 < 7.8.2.87.8.2.8
mcafeeweb_gateway>= 8.0.0 < 8.1.18.1.1
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccm1_systemd_239-34_on_cbl_mariner_1.0
opensuseleap
redhatenterprise_linux
redhatenterprise_linux_compute_node_eus
redhatenterprise_linux_desktop
redhatenterprise_linux_eus
redhatenterprise_linux_eus
redhatenterprise_linux_eus
redhatenterprise_linux_eus
redhatenterprise_linux_eus
redhatenterprise_linux_for_ibm_z_systems_eus
redhatenterprise_linux_for_ibm_z_systems_eus

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM