First published: Mon Jan 15 2018(Updated: )
In systemd prior to 234 a race condition exists between .mount and .automount units such that automount requests from kernel may not be serviced by systemd resulting in kernel holding the mountpoint and any processes that try to use said mount will hang. A race condition like this may lead to denial of service, until mount points are unmounted.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Systemd Project Systemd | <234 | |
Redhat Enterprise Linux | =7.0 | |
Redhat Enterprise Linux Aus | =7.4 | |
Redhat Enterprise Linux Aus | =7.6 | |
Redhat Enterprise Linux Desktop | =7.0 | |
Redhat Enterprise Linux Server | =7.0 | |
Redhat Enterprise Linux Server Aus | =7.4 | |
Redhat Enterprise Linux Server Aus | =7.6 | |
Redhat Enterprise Linux Server Eus | =7.4 | |
Redhat Enterprise Linux Server Eus | =7.5 | |
Redhat Enterprise Linux Server Eus | =7.6 | |
Redhat Enterprise Linux Server Tus | =7.4 | |
Redhat Enterprise Linux Server Tus | =7.6 | |
Redhat Enterprise Linux Workstation | =7.0 | |
Canonical Ubuntu Linux | =14.04 | |
Canonical Ubuntu Linux | =16.04 | |
Debian Debian Linux | =8.0 | |
redhat/systemd | <234 | 234 |
debian/systemd | 247.3-7+deb11u5 247.3-7+deb11u6 252.30-1~deb12u2 256.6-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2018-1049.
The severity of CVE-2018-1049 is medium (5.9).
The software versions affected by CVE-2018-1049 are systemd prior to 234 for Ubuntu and Redhat Enterprise Linux, and systemd versions up to 234 for Systemd Project.
To fix CVE-2018-1049 on Ubuntu, update the systemd package to version 234-1 or higher.
For more information about CVE-2018-1049, you can visit the following references: [Red Hat Bugzilla](https://bugzilla.redhat.com/show_bug.cgi?id=1534701), [Red Hat Security Advisory](https://access.redhat.com/errata/RHSA-2018:0260), [Ubuntu Security Notice](https://usn.ubuntu.com/3558-1/).