CVE-2018-1049: Race Condition
In systemd prior to 234 a race condition exists between .mount and .automount units such that automount requests from kernel may not be serviced by systemd resulting in kernel holding the mountpoint and any processes that try to use said mount will hang. A race condition like this may lead to denial of service, until mount points are unmounted.
Other sources
In systemd prior to 234 a race exists between .mount and .automount units such that automount requests from kernel may not be serviced by systemd resulting in kernel holding the mountpoint and any processes that try to use said mount will hang. A race like this may lead to denial of service, until mount points are unmounted.
References:
https://bugs.launchpad.net/ubuntu/+source/systemd/+bug/1709649
https://github.com/coreos/bugs/issues/1630
http://seclists.org/oss-sec/2018/q1/80
An upstream issue:
https://github.com/systemd/systemd/pull/5916
An upstream patch:
https://github.com/systemd/systemd/commit/e7d54bf58789545a9eb0b3964233defa0b007318
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2018-1049.
What is the severity of CVE-2018-1049?
The severity of CVE-2018-1049 is medium (5.9).
Which software versions are affected by CVE-2018-1049?
The software versions affected by CVE-2018-1049 are systemd prior to 234 for Ubuntu and Redhat Enterprise Linux, and systemd versions up to 234 for Systemd Project.
How can I fix CVE-2018-1049 on Ubuntu?
To fix CVE-2018-1049 on Ubuntu, update the systemd package to version 234-1 or higher.
Where can I find more information about CVE-2018-1049?
For more information about CVE-2018-1049, you can visit the following references: [Red Hat Bugzilla](https://bugzilla.redhat.com/show_bug.cgi?id=1534701), [Red Hat Security Advisory](https://access.redhat.com/errata/RHSA-2018:0260), [Ubuntu Security Notice](https://usn.ubuntu.com/3558-1/).