CVE-2018-16865 describes a memory allocation vulnerability in systemd-journald, affecting versions through v240, where an attacker can trigger a stack clash by sending numerous entries to the journal socket. This flaw impacts various Linux distributions including Canonical, Debian, Oracle, and Red Hat. With a CVSS score of 7.8 (HIGH), the vulnerability allows a local attacker, or a remote one if systemd-journal-remote is in use, to crash systemd-journald or execute code with journald privileges, indicating high impact on confidentiality, integrity, and availability. While there are no known Metasploit, Nuclei, or ExploitDB modules, community discussion suggests an exploit PoC for local root on i386 was anticipated, and media coverage highlighted the vulnerability's presence without immediate patches.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 240CPE matchmatch criteria | cpe:2.3:a:systemd_project:systemd:*:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:* | ||
7.3CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_server_aus:7.3:*:*:*:*:*:*:* | ||
7.6CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_server_aus:7.6:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2018-16865
Aug 11, 2020systemd: stack overflow when receiving many journald entries
Jan 9, 2019An allocation of memory without limits that could result in the stack clashing with another memory region was discovered in systemd-journald when many entries are sent to the journal socket. A local attacker or a remote one if systemd-journal-remote is used may use this flaw to crash systemd-journald or execute code with journald privileges. Versions through v240 are vulnerable.
Jan 8, 2019