CVE-2018-15686 is a vulnerability in the unit_deserialize function of systemd, affecting versions up to and including 239, which allows an attacker to inject arbitrary state during systemd re-execution via NotifyAccess. This flaw can manipulate systemd's behavior and potentially lead to root privilege escalation on systems running Canonical, Debian, or Oracle distributions. With a CVSS score of 7.8 (High), this vulnerability is locally exploitable with low attack complexity, granting high confidentiality, integrity, and availability impacts. While not listed in CISA's KEV catalog, public exploit code (EDB-45714) exists, though there is no evidence of active exploitation, Metasploit modules, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
16.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:* | ||
18.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:* | ||
18.10CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:18.10:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* | ||
<= 239CPE matchmatch criteria | cpe:2.3:a:systemd_project:systemd:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2018-15686
Aug 11, 2020systemd: line splitting via fgets() allows for state injection during daemon-reexec
Oct 26, 2018systemd: reexec state injection: fgets() on overlong lines leads to line splitting
Oct 9, 2018