cbcvebase.
CVE-2021-33910
published 2021-07-20

CVE-2021-33910: basic/unit-name.c in systemd prior to 246.15, 247.8, 248.5, and 249.1 has a Memory Allocation with an Excessive Size Value (involving strdupa and alloca for a…

medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
basic/unit-name.c in systemd prior to 246.15, 247.8, 248.5, and 249.1 has a Memory Allocation with an Excessive Size Value (involving strdupa and alloca for a pathname controlled by a local attacker) that results in an operating system crash.

Affected

17 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiansystemd< systemd 247.3-6 (bookworm)systemd 247.3-6 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
msrccm1_systemd_239-38_on_cbl_mariner_1.0
paloaltopan-os
systemd_projectsystemd< 246.15246.15
systemd_projectsystemd>= 0 < 247.3-6247.3-6
systemd_projectsystemd>= 0 < 247.3-6247.3-6
systemd_projectsystemd>= 0 < 247.3-6247.3-6
systemd_projectsystemd>= 0 < 247.3-6247.3-6
systemd_projectsystemd>= 0 < 237-3ubuntu10.49237-3ubuntu10.49
systemd_projectsystemd>= 0 < 245.4-4ubuntu3.10245.4-4ubuntu3.10
systemd_projectsystemd>= 0 < 229-4ubuntu21.31+esm1229-4ubuntu21.31+esm1
systemd_projectsystemd>= 247 < 247.8247.8
systemd_projectsystemd>= 248 < 248.5248.5
systemd_projectsystemd>= 249 < 249.1249.1

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv6.1MEDIUM