Heap out-of-bounds write in systemd - CVE-2018-15688

 

Heap out-of-bounds write in systemd - CVE-2018-15688

Published: October 29, 2018 / Updated: March 28, 2023


Vulnerability identifier: #VU15555
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-15688
CWE-ID: CWE-787
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause DoS condition or execute arbitrary code with elevated privileges.

The weakness exists within the written-from-scratch DHCPv6 client of the open-source Systemd management suite due to an out-of-bounds heap write in the DHCPv6 client when handling options sent by network adjacent DHCP servers. A remote attacker can supply maliciously crafted DHCPv6 packets, exploit the programming cockup, arbitrarily change parts of memory to crash or execute arbitrary code on the vulnerable Systemd-powered Linux machines.


Affected software

systemd
NetworkManager
Gentoo Linux
Arch Linux
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power
Opensuse
Fedora
Dell EMC Data Protection Search

How to mitigate CVE-2018-15688

Install update from vendor's website.

NetworkManager - addressed in versions 1.8.8-2.fc27, 1.10.12-2.fc28, 1.12.4-2.fc29
Dell EMC Data Protection Search - update to 18.2.1
systemd - addressed in versions 238-10.git438ac26.fc28, 239-6.git9f3aed1.fc29

External References

Related Security Bulletins