Systemd is a system software project that provides core initialization and service management for Linux distributions, with a presence across the vast majority of modern Linux deployments. The project's vulnerability footprint, concentrated in its single systemd product, spans a well-represented volume in the landscape and reflects the complexity of privileged system-level software: recurring weaknesses include improper privilege management, link-following conditions in file handling, resource-allocation limits that can be circumvented, and race conditions arising from concurrent access to shared system resources. Vulnerabilities affecting systemd have a moderate tendency toward serious severity outcomes and frequently acquire public exploit code, making disclosed flaws in this foundational component relevant to a broad population of systems. Defenders should treat systemd advisories as broadly applicable across their Linux infrastructure and prioritize patching given the component's privileged execution context and deep integration into system boot and service lifecycles; current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Systemd Project over time
Signals from CVEs in this vendor scope (55 CVEs).
55 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-9445HIGH In systemd through 233, certain sizes passed to dns_packet_new in systemd-resolved can cause it to allocate a buffer that's too small. A malicious DNS server can exploit this via a | Jun 28, 2017 | 7.5 | 56 | NO | NO |
CVE-2018-15686HIGH A vulnerability in unit_deserialize of systemd allows an attacker to supply arbitrary state across systemd re-execution via NotifyAccess. This can be used to improperly influence s | Oct 26, 2018 | 7.8 | 38 | NO | YES |
CVE-2017-15908HIGH In systemd 223 through 235, a remote DNS server can respond with a custom crafted DNS NSEC resource record to trigger an infinite loop in the dns_packet_read_type_window() function | Oct 26, 2017 | 7.5 | 37 | NO | NO |
CVE-2019-3844HIGH It was discovered that a systemd service that uses DynamicUser property can get new privileges through the execution of SUID binaries, which would allow to create binaries owned by | Apr 26, 2019 | 7.8 | 36 | NO | YES |
CVE-2019-3843HIGH It was discovered that a systemd service that uses DynamicUser property can create a SUID/SGID binary that would be allowed to run as the transient service UID/GID even after the s | Apr 26, 2019 | 7.8 | 36 | NO | YES |
CVE-2017-18078HIGH systemd-tmpfiles in systemd before 237 attempts to support ownership/permission changes on hardlinked files even if the fs.protected_hardlinks sysctl is turned off, which allows lo | Jan 29, 2018 | 7.8 | 35 | NO | YES |
CVE-2019-3842HIGH In systemd before v242-rc4, it was discovered that pam_systemd does not properly sanitize the environment before using the XDG_SEAT variable. It is possible for an attacker, in som | Apr 9, 2019 | 7.0 | 34 | NO | YES |
CVE-2017-1000082CRITICAL systemd v233 and earlier fails to safely parse usernames starting with a numeric digit (e.g. "0day"), running the service in question with root privileges rather than the user inte | Jul 7, 2017 | 9.8 | 34 | NO | NO |
CVE-2018-15687HIGH A race condition in chown_one() of systemd allows an attacker to cause systemd to set arbitrary permissions on arbitrary files. Affected releases are systemd versions up to and inc | Oct 26, 2018 | 7.0 | 33 | NO | YES |
CVE-2016-10156HIGH A flaw in systemd v228 in /src/basic/fs-util.c caused world writable suid files to be created when using the systemd timers features, allowing local attackers to escalate their pri | Jan 23, 2017 | 7.8 | 33 | NO | YES |
Signals from CVEs in this vendor scope (55 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Systemd Project.
Media articles that mention a CVE ID that affects a product developed by Systemd Project — matched by CVE ID, not by vendor name.