Permissions, Privileges, and Access Controls in systemd - CVE-2019-3843
Published: May 13, 2019 / Updated: January 29, 2020
Vulnerability details
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to an error in the process of binary creation, when the DynamicUser property is used to create a SUID or SGID binary for a systemd service. A local user can abuse the systemd functionality to execute arbitrary code on the target system with elevated privileges.
Affected software
systemd (Red Hat package)
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Fedora
How to mitigate CVE-2019-3843
systemd - update to
systemd (Red Hat package) - update to 239-29.el8
systemd - update to 241-8.git9ef65cb.fc30