CVE-2016-7796: Input Validation

Published Oct 5, 2016
·
Updated

It was found that systemd fails an assertion in managerinvokenotifymessage() when a zero-length message is received over its notification socket, causing it to no longer perform it's expected functionality. This issue was assigned CVE-2016-7795 and is tracked via bug 1380286. Upstream bug report is:

https://github.com/systemd/systemd/issues/4234

Older systemd versions either don't include the assert that is triggered in managerinvokenotifymessage(), or have managerprocessnotifyfd() function return error before calling managerinvokenotifymessage(). That error return still causes systemd to exit its main loop and freeze its execution in a similar way it's done in newer versions after failed assertion.

https://github.com/systemd/systemd/issues/4234#issuecomment-250441246

The managerinvokenotifymessage() function with assert was introduced in version v209:

https://github.com/systemd/systemd/commit/5ba6985b6c8ef85a8bcfeb1b65239c863436e75b#diff-ab78220e12703ee63fa1e6a2caa16bebR1319

However, the assertion was not reachable before the error return was removed in v219:

https://github.com/systemd/systemd/commit/d875aa8ce10b458dc218c0d98f4a82c8904d6d03

The systemd versions in Red Hat Enterprise Linux 7.0 and 7.1 are based on upstream v208, but include managerinvokenotifymessage() added via a separate backported patch. The assertion is not reachable, so those versions are affected by CVE-2016-7796, but not affected by CVE-2016-7795. Red Hat Enterprise Linux 7.2 rebased systemd to version v219. Therefore, those packages are no longer affected by CVE-2016-7796, but are now affected by CVE-2016-7795.

Other sources

The managerdispatchnotifyfd function in systemd allows local users to cause a denial of service (system hang) via a zero-length message received over a notify socket, which causes an error to be returned and the notification handler to be disabled.

MITRE

Affected Software

13 affected components
Systemd Project Systemd=209
Systemd Project Systemd=213
Systemd Project Systemd=214
Systemd Project Systemd=229
Novell Suse Linux Enterprise Software Development Kit=12.0-sp1
Novell Suse Linux Enterprise Desktop=12-sp1
Novell Suse Linux Enterprise Server=12.0
Novell Suse Linux Enterprise Server=12.0-sp1
Novell Suse Linux Enterprise Server For Sap=12.0
redhat Enterprise Linux Desktop=7.0
redhat Enterprise Linux Hpc Node=7.0
redhat Enterprise Linux Server=7.0
redhat Enterprise Linux Workstation=7.0

Event History

Oct 5, 2016
Data Sourced
11:07 AM
DescriptionSeverityAffected Software
Oct 13, 2016
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2016-7796?

CVE-2016-7796 is rated as Important due to its potential to disrupt systemd's functionality.

2

How do I fix CVE-2016-7796?

To fix CVE-2016-7796, upgrade your systemd package to a version that is not vulnerable.

3

Which versions of systemd are affected by CVE-2016-7796?

CVE-2016-7796 affects systemd versions 209, 213, 214, and 229.

4

What are the possible consequences of CVE-2016-7796?

The consequences of CVE-2016-7796 may include system instability and loss of service functionality.

5

Is CVE-2016-7796 being actively exploited?

As of now, there is no evidence that CVE-2016-7796 is being actively exploited in the wild.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203