CVE-2019-3843: High severity Systemd Project Systemd vulnerability
It was discovered that a systemd service that uses DynamicUser property can create a SUID/SGID binary that would be allowed to run as the transient service UID/GID even after the service is terminated. A local attacker may use this flaw to access resources that will be owned by a potentially different service in the future, when the UID/GID will be recycled.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID is CVE-2019-3843.
What is the severity of CVE-2019-3843?
The severity of CVE-2019-3843 is high with a severity value of 7.8.
Which software is affected by CVE-2019-3843?
The affected software includes Systemd, Fedora, Canonical Ubuntu Linux, Netapp HCI Management Node, Netapp Snapprotect, Netapp Solidfire, and Netapp Cn1610 Firmware.
How can a local attacker exploit CVE-2019-3843?
A local attacker may exploit CVE-2019-3843 by using a systemd service with DynamicUser property to create a SUID/SGID binary and access resources owned by a potentially different user.
Where can I find more information about CVE-2019-3843?
You can find more information about CVE-2019-3843 on the SecurityFocus website and the Bugzilla Red Hat website.