Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2018-15686

38
FAUCET Score

CVE-2018-15686 is a vulnerability in the unit_deserialize function of systemd, affecting versions up to and including 239, which allows an attacker to inject arbitrary state during systemd re-execution via NotifyAccess. This flaw can manipulate systemd's behavior and potentially lead to root privilege escalation on systems running Canonical, Debian, or Oracle distributions. With a CVSS score of 7.8 (High), this vulnerability is locally exploitable with low attack complexity, granting high confidentiality, integrity, and availability impacts. While not listed in CISA's KEV catalog, public exploit code (EDB-45714) exists, though there is no evidence of active exploitation, Metasploit modules, or significant community discussion.

Impacted Technologies

VendorProductVersion(s)CPE
16.04CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*
18.04CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
18.10CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:18.10:*:*:*:*:*:*:*
8.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
<= 239CPE matchmatch criteria
cpe:2.3:a:systemd_project:systemd:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.0

7.0HIGH

CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.0
Impact Score
5.9
CvssVersion
3.0

Exploit Intelligence

EPSS Score
2.28%
Probability of exploitation in next 30 days
EPSS Percentile
81.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
ExploitDB: EDB-45714 · Oct 29, 2018
This CVE's current EPSS score of 0.0228 is in the 97th percentile among its peer group of 17,061 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (14)

github_advisorypatch availablevia nvd_reference
View patch
microsoftpatch availablevia msrc
Product: 16951-16820Fixed in: -
microsoftpatch availablevia msrc
Product: cm1 systemd 239-31 on CBL Mariner 1.0Fixed in: -
microsoftpatch availablevia msrc
Product: CBL Mariner 1.0 ARMFixed in: 239-31
microsoftpatch availablevia msrc
Product: CBL Mariner 1.0 x64Fixed in: 239-31
redhatpatch availablevia redhat_api
Product: Red Hat Ansible Tower 3.4 for RHEL 7Fixed in: ansible-tower-37/ansible-tower-memcached-rhel7:1.4.15-28
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: systemd-0:219-67.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.4 Advanced Update SupportFixed in: systemd-0:219-42.el7_4.20
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.4 Telco Extended Update SupportFixed in: systemd-0:219-42.el7_4.20
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.4 Update Services for SAP SolutionsFixed in: systemd-0:219-42.el7_4.20
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.5 Extended Update SupportFixed in: systemd-0:219-57.el7_5.9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.6 Extended Update SupportFixed in: systemd-0:219-62.el7_6.11
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Ansible Tower 3.4 for RHEL 7Fixed in: ansible-tower-34/ansible-tower-memcached:1.4.15-28
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Ansible Tower 3.4 for RHEL 7Fixed in: ansible-tower-35/ansible-tower-memcached:1.4.15-28
View patch

Vendor Advisories (3)

microsoft2020-Aug/CVE-2018-15686

CVE-2018-15686

Aug 11, 2020
redhatCVE-2018-15686Moderate

systemd: line splitting via fgets() allows for state injection during daemon-reexec

Oct 26, 2018
microsoft2018-Oct/CVE-2018-15686Important

systemd: reexec state injection: fgets() on overlong lines leads to line splitting

Oct 9, 2018

References

access.redhat.com / errata/RHSA-2019:2091
Third Party Advisory
access.redhat.com / errata/RHSA-2019:3222
Third Party Advisory
access.redhat.com / errata/RHSA-2020:0593
Third Party Advisory
github.com / systemd/systemd/pull/10519
PatchThird Party Advisory
lists.apache.org / thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E
lists.debian.org / debian-lts-announce/2018/11/msg00017.html
Mailing ListThird Party Advisory
security.gentoo.org / glsa/201810-10
Third Party Advisory
usn.ubuntu.com / 3816-1
Third Party Advisory
exploit-db.com / exploits/45714
ExploitThird Party AdvisoryVDB Entry
oracle.com / /security-alerts/cpujul2021.html
Third Party Advisory
securityfocus.com / bid/105747
Third Party AdvisoryVDB Entry