Back

HIGH

systemd: reexec state injection: fgets() on overlong lines leads to line splitting

Published Oct 26, 2018

Description

A vulnerability in unit_deserialize of systemd allows an attacker to supply arbitrary state across systemd re-execution via NotifyAccess. This can be used to improperly influence systemd execution and possibly lead to root privilege escalation. Affected releases are systemd versions up to and including 239.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (15)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner canonical
Published Oct 26, 2018
Updated Jun 9, 2025
Reserved Aug 22, 2018
CISA Vulnrichment
Updated Jun 9, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Oct 26, 2018