Back

HIGH

systemd: chown_one() can dereference symlinks

Published Oct 26, 2018

Description

A race condition in chown_one() of systemd allows an attacker to cause systemd to set arbitrary permissions on arbitrary files. Affected releases are systemd versions up to and including 239.

Affected products

Remediation

Red Hat statement

This issue did not affect the versions of systemd as shipped with Red Hat Enterprise Linux 7 as the vulnerable code was introduced in a newer version of the package.

References (10)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner canonical
Published Oct 26, 2018
Updated Jun 9, 2025
Reserved Aug 22, 2018

CISA Vulnrichment

Updated Jun 9, 2025

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

Severity Moderate
Public date Oct 26, 2018
Bugzilla 1639076

ENISA EUVD

Assigner canonical
Published Oct 26, 2018
Updated Jun 9, 2025

GitHub

No data