A heap use-after-free vulnerability was found in systemd before version v245-rc1, where asynchronous Polkit queries are performed while handling dbus messages. A local unprivileged attacker can abuse this flaw to crash systemd services or potentially execute code and elevate their privileges, by sending specially crafted dbus messages.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3063-1 | systemd security update |
EUVD |
EUVD-2020-12567 | A heap use-after-free vulnerability was found in systemd before version v245-rc1, where asynchronous Polkit queries are performed while handling dbus messages. A local unprivileged attacker can abuse this flaw to crash systemd services or potentially execute code and elevate their privileges, by sending specially crafted dbus messages. |
Ubuntu USN |
USN-4269-1 | systemd vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 09 Jun 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2025-06-09T15:53:12.293Z
Reserved: 2019-11-27T00:00:00.000Z
Link: CVE-2020-1712
Updated: 2024-08-04T06:46:30.849Z
Status : Modified
Published: 2020-03-31T17:15:26.577
Modified: 2024-11-21T05:11:13.433
Link: CVE-2020-1712
OpenCVE Enrichment
No data.
Debian DLA
EUVD
Ubuntu USN