First published: Tue Jan 21 2020(Updated: )
An issue was discovered in button_open in login/logind-button.c in systemd before 243. When executing the udevadm trigger command, a memory leak may occur.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Systemd Project Systemd | <243 | |
Canonical Ubuntu Linux | =16.04 | |
Canonical Ubuntu Linux | =18.04 | |
Canonical Ubuntu Linux | =19.10 | |
Fedoraproject Fedora | =30 | |
openSUSE Leap | =15.1 | |
Netapp Active Iq Unified Manager Vmware Vsphere | ||
Netapp Cloud Backup | ||
Netapp Steelstore Cloud Integrated Storage | ||
debian/systemd | 247.3-7+deb11u5 247.3-7+deb11u6 252.30-1~deb12u2 256.6-1 256.7-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-20386 is a vulnerability discovered in systemd, allowing a memory leak to occur when executing the udevadm trigger command.
CVE-2019-20386 has a severity value of 2.4, which is considered low.
CVE-2019-20386 affects systemd versions up to and excluding 243, as well as specific versions of Ubuntu, Fedora, openSUSE Leap, Apple iPadOS, Netapp Active IQ Unified Manager, Netapp Cloud Backup, and Netapp Steelstore Cloud Integrated Storage.
To fix CVE-2019-20386 on Ubuntu, update the systemd package to version 243-5 or later.
More information about CVE-2019-20386 can be found at the following links: [OpenSUSE Security Announce](http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00014.html), [GitHub Commit](https://github.com/systemd/systemd/commit/b2774a3ae692113e1f47a336a6c09bac9cfb49ad), [Fedora Project Mailing List](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HZPCOMW5X6IZZXASCDD2CNW2DLF3YADC/).