Description
It was discovered that a systemd service that uses DynamicUser property can create a SUID/SGID binary that would be allowed to run as the transient service UID/GID even after the service is terminated. A local attacker may use this flaw to access resources that will be owned by a potentially different service in the future, when the UID/GID will be recycled.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-13463 | It was discovered that a systemd service that uses DynamicUser property can create a SUID/SGID binary that would be allowed to run as the transient service UID/GID even after the service is terminated. A local attacker may use this flaw to access resources that will be owned by a potentially different service in the future, when the UID/GID will be recycled. |
Ubuntu USN |
USN-4269-1 | systemd vulnerabilities |
References
History
Mon, 09 Jun 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Subscriptions
Canonical
Subscribe
Ubuntu Linux
Subscribe
Fedoraproject
Subscribe
Fedora
Subscribe
Netapp
Subscribe
Cn1610
Subscribe
Cn1610 Firmware
Subscribe
Hci Management Node
Subscribe
Snapprotect
Subscribe
Solidfire
Subscribe
Redhat
Subscribe
Enterprise Linux
Subscribe
Systemd Project
Subscribe
Systemd
Subscribe
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2025-06-09T15:49:53.235Z
Reserved: 2019-01-03T00:00:00.000Z
Link: CVE-2019-3843
Updated: 2024-08-04T19:19:18.567Z
Status : Modified
Published: 2019-04-26T21:29:00.360
Modified: 2024-11-21T04:42:41.073
Link: CVE-2019-3843
OpenCVE Enrichment
No data.
EUVD
Ubuntu USN