CVE-2021-33910
published 2021-07-20CVE-2021-33910: basic/unit-name.c in systemd prior to 246.15, 247.8, 248.5, and 249.1 has a Memory Allocation with an Excessive Size Value (involving strdupa and alloca for a…
PriorityP431medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
8.65%
94.5th percentile
basic/unit-name.c in systemd prior to 246.15, 247.8, 248.5, and 249.1 has a Memory Allocation with an Excessive Size Value (involving strdupa and alloca for a pathname controlled by a local attacker) that results in an operating system crash.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | systemd | < systemd 247.3-6 (bookworm) | systemd 247.3-6 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| msrc | cm1_systemd_239-38_on_cbl_mariner_1.0 | — | — |
| paloalto | pan-os | — | — |
| systemd_project | systemd | < 246.15 | 246.15 |
| systemd_project | systemd | >= 0 < 247.3-6 | 247.3-6 |
| systemd_project | systemd | >= 0 < 247.3-6 | 247.3-6 |
| systemd_project | systemd | >= 0 < 247.3-6 | 247.3-6 |
| systemd_project | systemd | >= 0 < 247.3-6 | 247.3-6 |
| systemd_project | systemd | >= 0 < 237-3ubuntu10.49 | 237-3ubuntu10.49 |
| systemd_project | systemd | >= 0 < 245.4-4ubuntu3.10 | 245.4-4ubuntu3.10 |
| systemd_project | systemd | >= 0 < 229-4ubuntu21.31+esm1 | 229-4ubuntu21.31+esm1 |
| systemd_project | systemd | >= 247 < 247.8 | 247.8 |
| systemd_project | systemd | >= 248 < 248.5 | 248.5 |
| systemd_project | systemd | >= 249 < 249.1 | 249.1 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
osv6.1MEDIUM
vendor_ubuntu6.1MEDIUM
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5337-wcgc-wcvp: basic/unit-name
ghsa_unreviewed·2022-05-24
CVE-2021-33910 [MEDIUM] CWE-770 GHSA-5337-wcgc-wcvp: basic/unit-name
basic/unit-name.c in systemd 220 through 248 has a Memory Allocation with an Excessive Size Value (involving strdupa and alloca for a pathname controlled by a local attacker) that results in an operating system crash.
OSV
systemd vulnerabilities
osv·2021-07-20·CVSS 6.1
CVE-2021-33910 [MEDIUM] systemd vulnerabilities
systemd vulnerabilities
USN-5013-1 fixed several vulnerabilities in systemd. This update provides
the corresponding update for Ubuntu 16.04 ESM.
Original advisory details:
It was discovered that systemd incorrectly handled certain mount paths. A
local attacker could possibly use this issue to cause systemd to crash,
resulting in a denial of service. (CVE-2021-33910)
Mitchell Frank discovered that systemd incorrectly handled DHCP FORCERENEW
packets. A remote attacker could possibly use this issue to reconfigure
servers. (CVE-2020-13529)
OSV
systemd vulnerabilities
osv·2021-07-20·CVSS 6.1
CVE-2021-33910 [MEDIUM] systemd vulnerabilities
systemd vulnerabilities
It was discovered that systemd incorrectly handled certain mount paths. A
local attacker could possibly use this issue to cause systemd to crash,
resulting in a denial of service. (CVE-2021-33910)
Mitchell Frank discovered that systemd incorrectly handled DHCP FORCERENEW
packets. A remote attacker could possibly use this issue to reconfigure
servers. (CVE-2020-13529)
OSV
CVE-2021-33910: basic/unit-name
osv·2021-07-20·CVSS 5.5
CVE-2021-33910 [MEDIUM] CVE-2021-33910: basic/unit-name
basic/unit-name.c in systemd prior to 246.15, 247.8, 248.5, and 249.1 has a Memory Allocation with an Excessive Size Value (involving strdupa and alloca for a pathname controlled by a local attacker) that results in an operating system crash.
Palo Alto
PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
vendor_paloalto·2024-02-14·CVSS 9.8
CVE-2017-18342 [CRITICAL] PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS software. While PAN-OS software may include the
CVEs: CVE-2017-18342, CVE-2017-8923, CVE-2017-9120, CVE-2019-1551, CVE-2019-16865, CVE-2019-16905, CVE-2019-19523, CVE-2019-19528, CVE-2019-19911, CVE-2020-0404, CVE-2020-0431, CVE-2020-0466, CVE-2020-10379, CVE-2020-11538, CVE-2020-11608, CVE-2020-12114, CVE-2020-12321, CVE-2020-12362, CVE-2020-12363, CVE-2020-12364, CVE-2020-13757, CVE-2020-14314, CVE-2020-14351, CVE-2020-15778, CVE-2020-1967, CVE-2020-24394, CVE-2020-24504, CVE-2020-25211, CVE-2020-25212, CVE-2020-25284, CVE-2020-25285, CVE-2020-25717, CVE-2020-26541, CVE-2020-2715
CISA ICS
Siemens SCALANCE LPE9403 Third-Party Vulnerabilities
cisa_ics·2022-06-16·CVSS 9.8
[CRITICAL] Siemens SCALANCE LPE9403 Third-Party Vulnerabilities
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SCALANCE LPE9403 Third-Party Vulnerabilities
Last RevisedJune 16, 2022
Alert CodeICSA-22-167-09
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely, low attack complexity
- Vendor: Siemens
- Equipment: SCALANCE LPE9403
- Vulnerabilities: Multiple
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could cause crashes and unrestricted file access, impacting the product’s confidentiality, integrity, and availability.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The following versions of SCALANCE LPE9403 (Local Processing
Ubuntu
systemd vulnerabilities
vendor_ubuntu·2021-07-20·CVSS 6.1
CVE-2020-13529 [MEDIUM] systemd vulnerabilities
Title: systemd vulnerabilities
Summary: Several security issues were fixed in systemd.
USN-5013-1 fixed several vulnerabilities in systemd. This update provides
the corresponding update for Ubuntu 16.04 ESM.
Original advisory details:
It was discovered that systemd incorrectly handled certain mount paths. A
local attacker could possibly use this issue to cause systemd to crash,
resulting in a denial of service. (CVE-2021-33910)
Mitchell Frank discovered that systemd incorrectly handled DHCP FORCERENEW
packets. A remote attacker could possibly use this issue to reconfigure
servers. (CVE-2020-13529)
Instructions: After a standard system update you need to reboot your computer to make all
the necessary changes.
Red Hat
systemd: uncontrolled allocation on the stack in function unit_name_path_escape leads to crash
vendor_redhat·2021-07-20·CVSS 5.5
CVE-2021-33910 [MEDIUM] CWE-400 systemd: uncontrolled allocation on the stack in function unit_name_path_escape leads to crash
systemd: uncontrolled allocation on the stack in function unit_name_path_escape leads to crash
basic/unit-name.c in systemd prior to 246.15, 247.8, 248.5, and 249.1 has a Memory Allocation with an Excessive Size Value (involving strdupa and alloca for a pathname controlled by a local attacker) that results in an operating system crash.
A flaw was found in systemd. The use of alloca function with an uncontrolled size in function unit_name_path_escape allows a local attacker, able to mount a filesystem on a very long path, to crash systemd and the whole system by allocating a very large space in the stack. The highest threat from this vulnerability is to the system availability.
Statement: This issue did not affect the versions of systemd as shipped with Red Hat Enterprise Linux 7 as they
Ubuntu
systemd vulnerabilities
vendor_ubuntu·2021-07-20·CVSS 6.1
CVE-2020-13529 [MEDIUM] systemd vulnerabilities
Title: systemd vulnerabilities
Summary: Several security issues were fixed in systemd.
It was discovered that systemd incorrectly handled certain mount paths. A
local attacker could possibly use this issue to cause systemd to crash,
resulting in a denial of service. (CVE-2021-33910)
Mitchell Frank discovered that systemd incorrectly handled DHCP FORCERENEW
packets. A remote attacker could possibly use this issue to reconfigure
servers. (CVE-2020-13529)
Instructions: After a standard system update you need to reboot your computer to make all
the necessary changes.
Microsoft
basic/unit-name.c in systemd prior to 246.15 247.8 248.5 and 249.1 has a Memory Allocation with an Excessive Size Value (involving strdupa and alloca for a pathname controlled by a local attacker) tha
vendor_msrc·2021-07-13·CVSS 5.5
CVE-2021-33910 [MEDIUM] CWE-770 basic/unit-name.c in systemd prior to 246.15 247.8 248.5 and 249.1 has a Memory Allocation with an Excessive Size Value (involving strdupa and alloca for a pathname controlled by a local attacker) tha
basic/unit-name.c in systemd prior to 246.15 247.8 248.5 and 249.1 has a Memory Allocation with an Excessive Size Value (involving strdupa and alloca for a pathname controlled by a local attacker) that results in an operating system crash.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional pro
Debian
CVE-2021-33910: systemd - basic/unit-name.c in systemd prior to 246.15, 247.8, 248.5, and 249.1 has a Memo...
vendor_debian·2021·CVSS 5.5
CVE-2021-33910 [MEDIUM] CVE-2021-33910: systemd - basic/unit-name.c in systemd prior to 246.15, 247.8, 248.5, and 249.1 has a Memo...
basic/unit-name.c in systemd prior to 246.15, 247.8, 248.5, and 249.1 has a Memory Allocation with an Excessive Size Value (involving strdupa and alloca for a pathname controlled by a local attacker) that results in an operating system crash.
Scope: local
bookworm: resolved (fixed in 247.3-6)
bullseye: resolved (fixed in 247.3-6)
forky: resolved (fixed in 247.3-6)
sid: resolved (fixed in 247.3-6)
trixie: resolved (fixed in 247.3-6)
No detection rules found.
No public exploits indexed.
Qualys
CVE-2021-33910: Denial of Service (Stack Exhaustion) in systemd (PID 1) | Qualys
blogs_qualys·2021-07-20·CVSS 7.8
CVE-2021-33910 [HIGH] CVE-2021-33910: Denial of Service (Stack Exhaustion) in systemd (PID 1) | Qualys
#### Table of Contents
- About systemd
- Impact
- Disclosure Timeline
- Technical Details
- Solution
- Qualys Coverage
- Discover Vulnerable Linux Servers Using Qualys VMDR
- Prioritize Based on RTIs
- Detect Impacted Assets with Threat Protection
- Dashboard
- Vendor References
- Frequently Asked Questions (FAQs)
The Qualys Research Team has discovered a stack exhaustion denial-of-service vulnerability in systemd, a near-ubiquitous utility available on major Linux operating systems. Any unprivileged user can exploit this vulnerability to crash systemd and hence the entire operating system (a kernel panic).
## About systemd
`systemd` is a software suite that’s included in most Linux-based OSes. It provides an array of system components for Linux operating systems. It provides a system
Qualys
Sequoia: A Local Privilege Escalation Vulnerability in Linux’s Filesystem Layer (CVE-2021-33909) | Qualys
blogs_qualys·2021-07-20·CVSS 7.8
CVE-2021-33909 [HIGH] Sequoia: A Local Privilege Escalation Vulnerability in Linux’s Filesystem Layer (CVE-2021-33909) | Qualys
#### Table of Contents
- About Linux Filesystem
- Impact
- Disclosure Timeline
- Proof of Concept Video
- Technical Details
- Solution
- Qualys Coverage
- Discover Vulnerable Linux Servers Using Qualys VMDR
- Dashboard
- Vendor References
- Frequently Asked Questions (FAQs)
The Qualys Research Team has discovered a size_t-to-int type conversion vulnerability in the Linux Kernel’s filesystem layer affecting most Linux operating systems. Any unprivileged user can gain root privileges on a vulnerable host by exploiting this vulnerability in a default configuration.
## About Linux Filesystem
A file system is an organization of data and metadata on a storage device. It controls how the data is stored and retrieved, and its most important function is to manage user data. The Linux file syste
Qualys
CVE-2021-33910: Denial of Service (Stack Exhaustion) in systemd (PID 1)
blogs_qualys·2021-07-20·CVSS 7.8
[HIGH] CVE-2021-33910: Denial of Service (Stack Exhaustion) in systemd (PID 1)
## Table of Contents
About systemd
Impact
Disclosure Timeline
Technical Details
Solution
Qualys Coverage
Discover Vulnerable Linux Servers Using Qualys VMDR
Prioritize Based on RTIs
Detect Impacted Assets with Threat Protection
Dashboard
Vendor References
Frequently Asked Questions (FAQs)
The Qualys Research Team has discovered a stack exhaustion denial-of-service vulnerability in systemd, a near-ubiquitous utility available on major Linux operating systems. Any unprivileged user can exploit this vulnerability to crash systemd and hence the entire operating system (a kernel panic).
## About systemd
systemd
## Impact
This vulnerability was introduced in systemd v220 (April 2015) by commit 7410616c (“core: rework unit name validation and manipulation logic”), which replaced
Qualys
Sequoia: A Local Privilege Escalation Vulnerability in Linux’s Filesystem Layer (CVE-2021-33909)
blogs_qualys·2021-07-20·CVSS 7.8
[HIGH] Sequoia: A Local Privilege Escalation Vulnerability in Linux’s Filesystem Layer (CVE-2021-33909)
## Table of Contents
About Linux Filesystem
Impact
Disclosure Timeline
Proof of Concept Video
Technical Details
Solution
Qualys Coverage
Discover Vulnerable Linux Servers Using Qualys VMDR
Dashboard
Vendor References
Frequently Asked Questions (FAQs)
The Qualys Research Team has discovered a size_t-to-int type conversion vulnerability in the Linux Kernel’s filesystem layer affecting most Linux operating systems. Any unprivileged user can gain root privileges on a vulnerable host by exploiting this vulnerability in a default configuration.
## About Linux Filesystem
A file system is an organization of data and metadata on a storage device. It controls how the data is stored and retrieved, and its most important function is to manage user data. The Linux file system interface is
http://packetstormsecurity.com/files/163621/Sequoia-A-Deep-Root-In-Linuxs-Filesystem-Layer.htmlhttp://www.openwall.com/lists/oss-security/2021/08/04/2http://www.openwall.com/lists/oss-security/2021/08/17/3http://www.openwall.com/lists/oss-security/2021/09/07/3https://cert-portal.siemens.com/productcert/pdf/ssa-222547.pdfhttps://github.com/systemd/systemd-stable/commit/4a1c5f34bd3e1daed4490e9d97918e504d19733bhttps://github.com/systemd/systemd-stable/commit/764b74113e36ac5219a4b82a05f311b5a92136cehttps://github.com/systemd/systemd-stable/commit/b00674347337b7531c92fdb65590ab253bb57538https://github.com/systemd/systemd-stable/commit/cfd14c65374027b34dbbc4f0551456c5dc2d1f61https://github.com/systemd/systemd/commit/b34a4f0e6729de292cb3b0c03c1d48f246ad896bhttps://github.com/systemd/systemd/pull/20256/commits/441e0115646d54f080e5c3bb0ba477c892861ab9https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2LSDMHAKI4LGFOCSPXNVVSEWQFAVFWR7/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/42TMJVNYRY65B4QCJICBYOEIVZV3KUYI/https://security.gentoo.org/glsa/202107-48https://security.netapp.com/advisory/ntap-20211104-0008/https://www.debian.org/security/2021/dsa-4942https://www.openwall.com/lists/oss-security/2021/07/20/2http://packetstormsecurity.com/files/163621/Sequoia-A-Deep-Root-In-Linuxs-Filesystem-Layer.htmlhttp://www.openwall.com/lists/oss-security/2021/08/04/2http://www.openwall.com/lists/oss-security/2021/08/17/3http://www.openwall.com/lists/oss-security/2021/09/07/3https://cert-portal.siemens.com/productcert/pdf/ssa-222547.pdfhttps://github.com/systemd/systemd-stable/commit/4a1c5f34bd3e1daed4490e9d97918e504d19733bhttps://github.com/systemd/systemd-stable/commit/764b74113e36ac5219a4b82a05f311b5a92136cehttps://github.com/systemd/systemd-stable/commit/b00674347337b7531c92fdb65590ab253bb57538https://github.com/systemd/systemd-stable/commit/cfd14c65374027b34dbbc4f0551456c5dc2d1f61https://github.com/systemd/systemd/commit/b34a4f0e6729de292cb3b0c03c1d48f246ad896bhttps://github.com/systemd/systemd/pull/20256/commits/441e0115646d54f080e5c3bb0ba477c892861ab9https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2LSDMHAKI4LGFOCSPXNVVSEWQFAVFWR7/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/42TMJVNYRY65B4QCJICBYOEIVZV3KUYI/https://security.gentoo.org/glsa/202107-48https://security.netapp.com/advisory/ntap-20211104-0008/https://www.debian.org/security/2021/dsa-4942https://www.openwall.com/lists/oss-security/2021/07/20/2
2021-07-20
Published