systemd: Mishandled symlinks in systemd-tmpfiles allows local users to obtain ownership of arbitrary files
Published Feb 13, 2018
7.8
HIGHCVSS 3.1
EPSS 0.53%
Description
systemd-tmpfiles in systemd through 237 mishandles symlinks present in non-terminal path components, which allows local users to obtain ownership of arbitrary files via vectors involving creation of a directory and a file under that directory, and later replacing that directory with a symlink. This occurs even if the fs.protected_symlinks sysctl is turned on.
Affected products
No data.
Configuration 1
- ≤ 237
Configuration 2
- 16.04
- 18.04
- 18.10
- 42.3
No data.
Red Hat Enterprise Linux 7
systemd
Will not fix
Red Hat Enterprise Linux 8
systemd
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | systemd | Will not fix | n/a |
| Red Hat Enterprise Linux 8 | systemd | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This flaw affects in particular those systems where custom tmpfiles files are configured (e.g. in /etc/tmpfiles.d). Indeed systemd-tmpfiles installed by system packages set privileges of a directory either to root or to a service specific user and not to interactive users. Even in case they provide one of the vulnerable tmpfiles configuration file (e.g. recursive "Z" type entries), an attacker would still need to perform the attack as the service specific user, which means they would first need to compromise that service. Moreover, systemd-tmpfiles service is automatically executed only when the system boots, when it is very unlikely an attacker has already a chance to perform any action at all. Otherwise, an attacker would have to wait for an administrator to manually run the `systemd-tmpfiles --create` command.
Red Hat mitigation
There is no known mitigation available.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
AV:L/AC:L/Au:N/C:C/I:C/A:C
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Jun 9, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Table of values (8 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.53% (0.00525) | 42.38th | v5 (v2026.06.15) |
| Sep 20, 2026 | 0.53% (0.00525) | 43.44th | v5 (v2026.06.15) |
| Jul 20, 2024 | 0.04% (0.00042) | 5.06th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.04% (0.00042) | 5.63th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.03% (0.01034) | 41.69th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.03% (0.01034) | 20.32th | v2 (v2022.01.01) |
| Feb 3, 2022 | 0.78% (0.00777) | 21.08th | v5 (v2026.06.15) |
| Apr 14, 2021 | 0.56% (0.00555) | 0.00th | v1 |
References (10)
- http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00062.html vendor-advisoryx_refsource_SUSEThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2018-6954 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1545017 Issue Tracking
- https://github.com/systemd/systemd/issues/7986 x_refsource_MISCExploitIssue TrackingPatchThird Party Advisory
- https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E mailing-listx_refsource_MLIST
- https://nvd.nist.gov/vuln/detail/CVE-2018-6954
- https://usn.ubuntu.com/3816-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/3816-2/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2018-6954
| Link | Providers | Tags |
|---|---|---|
| http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00062.html | vendor-advisoryx_refsource_SUSEThird Party Advisory | |
| https://access.redhat.com/security/cve/CVE-2018-6954 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1545017 | Issue Tracking | |
| https://github.com/systemd/systemd/issues/7986 | x_refsource_MISCExploitIssue TrackingPatchThird Party Advisory | |
| https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E | mailing-listx_refsource_MLIST | |
| https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E | mailing-listx_refsource_MLIST | |
| https://nvd.nist.gov/vuln/detail/CVE-2018-6954 | ||
| https://usn.ubuntu.com/3816-1/ | vendor-advisoryx_refsource_UBUNTUThird Party Advisory | |
| https://usn.ubuntu.com/3816-2/ | vendor-advisoryx_refsource_UBUNTUThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2018-6954 |
Change history (0)
No recorded changes yet.