CVE-2018-16866 is an out-of-bounds read vulnerability in systemd-journald, affecting versions v221 to v239 of systemd, as well as products from Canonical, Debian, NetApp, and Red Hat. A local attacker can exploit this flaw by crafting log messages ending with a colon to disclose process memory data. The vulnerability has a CVSS score of 3.3 (LOW), indicating low attack complexity and local access requirements, with a potential impact of limited data confidentiality. There is no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or KEV entry, though community discussion suggests potential for a local root shell exploit.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 221, <= 239CPE matchmatch criteria | cpe:2.3:a:systemd_project:systemd:*:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* | ||
16.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:* | ||
18.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:* | ||
18.10CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:18.10:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2018-16866
Aug 11, 2020systemd: out-of-bounds read when parsing a crafted syslog message
Jan 9, 2019An out of bounds read was discovered in systemd-journald in the way it parses log messages that terminate with a colon ':'. A local attacker can use this flaw to disclose process memory data. Versions from v221 to v239 are vulnerable.
Jan 8, 2019