systemd: memory leak in button_open() in login/logind-button.c when udev events are received
Published Jan 21, 2020
5.1
MEDIUMCVSS 3.1
EPSS 0.43%
Description
An issue was discovered in button_open in login/logind-button.c in systemd before 243. When executing the udevadm trigger command, a memory leak may occur.
Affected products
No data.
Configuration 1
- < 243
Configuration 2
- 16.04
- 18.04
- 19.10
- 30
- 15.1
Configuration 3
- n/a
- n/a
- n/a
No data.
Red Hat Enterprise Linux 7
systemd-0:219-78.el7
Fixed · RHSA-2020:4007
Red Hat Enterprise Linux 8
systemd-0:239-40.el8
Fixed · RHSA-2020:4553
Red Hat OpenShift Do
openshiftdo/odo-init-image-rhel7:1.1.3-2
Fixed · RHSA-2021:0949
Red Hat OpenShift Container Platform 4
systemd
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | systemd-0:219-78.el7 | Fixed | RHSA-2020:4007 |
| Red Hat Enterprise Linux 8 | systemd-0:239-40.el8 | Fixed | RHSA-2020:4553 |
| Red Hat OpenShift Do | openshiftdo/odo-init-image-rhel7:1.1.3-2 | Fixed | RHSA-2021:0949 |
| Red Hat OpenShift Container Platform 4 | systemd | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
The version of systemd delivered in OpenShift Container Platform 4.1 and included in CoreOS images has been superseded by the version delivered in Red Hat Enterprise Linux 8. CoreOS updates for systemd in will be consumed from Red Hat Enterprise Linux 8 channels.
References (10)
- http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00014.html vendor-advisoryx_refsource_SUSEThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2019-20386 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1793979 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-10938 Advisory
- https://github.com/systemd/systemd/commit/b2774a3ae692113e1f47a336a6c09bac9cfb49ad x_refsource_MISCPatchThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HZPCOMW5X6IZZXASCDD2CNW2DLF3YADC/ vendor-advisoryx_refsource_FEDORA
- https://nvd.nist.gov/vuln/detail/CVE-2019-20386
- https://security.netapp.com/advisory/ntap-20200210-0002/ x_refsource_CONFIRMThird Party Advisory
- https://usn.ubuntu.com/4269-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-20386
| Link | Providers | Tags |
|---|---|---|
| http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00014.html | vendor-advisoryx_refsource_SUSEThird Party Advisory | |
| https://access.redhat.com/security/cve/CVE-2019-20386 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1793979 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-10938 | Advisory | |
| https://github.com/systemd/systemd/commit/b2774a3ae692113e1f47a336a6c09bac9cfb49ad | x_refsource_MISCPatchThird Party Advisory | |
| https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HZPCOMW5X6IZZXASCDD2CNW2DLF3YADC/ | vendor-advisoryx_refsource_FEDORA | |
| https://nvd.nist.gov/vuln/detail/CVE-2019-20386 | ||
| https://security.netapp.com/advisory/ntap-20200210-0002/ | x_refsource_CONFIRMThird Party Advisory | |
| https://usn.ubuntu.com/4269-1/ | vendor-advisoryx_refsource_UBUNTUThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2019-20386 |
Change history (0)
No recorded changes yet.