CVE-2018-16864 describes a memory allocation vulnerability in systemd-journald, affecting versions through v240, where long command-line arguments can cause a stack clash. This flaw impacts various Linux distributions including Canonical, Debian, Oracle, and Red Hat. With a CVSS score of 7.8 (HIGH), a local attacker can exploit this with low complexity to achieve high impact in confidentiality, integrity, and availability, potentially leading to systemd-journald crashes or privilege escalation. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered some community discussion and media coverage, indicating awareness despite its inactive status on hot lists.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 240CPE matchmatch criteria | cpe:2.3:a:systemd_project:systemd:*:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:* | ||
7.4CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_server:7.4:*:*:*:*:*:*:* | ||
7.5CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_server:7.5:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2018-16864
Aug 11, 2020systemd: stack overflow when calling syslog from a command with long cmdline
Jan 9, 2019An allocation of memory without limits that could result in the stack clashing with another memory region was discovered in systemd-journald when a program with long command line arguments calls syslog. A local attacker may use this flaw to crash systemd-journald or escalate his privileges. Versions through v240 are vulnerable.
Jan 8, 2019