Description
An issue was discovered in sd-bus in systemd 239. bus_process_object() in libsystemd/sd-bus/bus-objects.c allocates a variable-length stack buffer for temporarily storing the object path of incoming D-Bus messages. An unprivileged local user can exploit this by sending a specially crafted message to PID1, causing the stack pointer to jump over the stack guard pages into an unmapped memory region and trigger a denial of service (systemd PID1 crash and kernel panic).
Published: 2019-03-17
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-1684-1 systemd security update
Debian DSA Debian DSA DSA-4393-1 systemd security update
EUVD EUVD EUVD-2019-16014 An issue was discovered in sd-bus in systemd 239. bus_process_object() in libsystemd/sd-bus/bus-objects.c allocates a variable-length stack buffer for temporarily storing the object path of incoming D-Bus messages. An unprivileged local user can exploit this by sending a specially crafted message to PID1, causing the stack pointer to jump over the stack guard pages into an unmapped memory region and trigger a denial of service (systemd PID1 crash and kernel panic).
Ubuntu USN Ubuntu USN USN-3891-1 systemd vulnerability
History

No history.

Subscriptions

Canonical Ubuntu Linux
Debian Debian Linux
Fedoraproject Fedora
Mcafee Web Gateway
Netapp Active Iq Performance Analytics Services
Opensuse Leap
Redhat Enterprise Linux Enterprise Linux Compute Node Eus Enterprise Linux Desktop Enterprise Linux Eus Enterprise Linux For Ibm Z Systems Eus Enterprise Linux For Power Big Endian Eus Enterprise Linux For Power Little Endian Enterprise Linux For Power Little Endian Eus Enterprise Linux Server Enterprise Linux Server Aus Enterprise Linux Server Eus Enterprise Linux Server For Power Little Endian Update Services For Sap Solutions Enterprise Linux Server Tus Enterprise Linux Server Update Services For Sap Solutions Enterprise Linux Workstation Rhel Aus Rhel E4s Rhel Eus Rhel Tus
Systemd Project Systemd
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T20:23:21.049Z

Reserved: 2019-01-16T00:00:00.000Z

Link: CVE-2019-6454

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-03-21T16:01:08.203

Modified: 2024-11-21T04:46:28.867

Link: CVE-2019-6454

cve-icon Redhat

Severity : Important

Publid Date: 2019-02-18T00:00:00Z

Links: CVE-2019-6454 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses