Input validation error in systemd - CVE-2020-13776

 

Input validation error in systemd - CVE-2020-13776

Published: July 6, 2020 / Updated: July 27, 2020


Vulnerability identifier: #VU29539
CSH Severity: Low
CVSS v4: 9.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H]
CVE-ID: CVE-2020-13776
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to systemd mishandles numerical usernames such as ones composed of decimal digits or 0x followed by hex digits, as demonstrated by use of root privileges when privileges of the 0x0 user account were intended.


Affected software

systemd
systemd (Red Hat package)
systemd-udev
systemd-tests
systemd-pam
systemd-libs
systemd-journal-remote
systemd-devel
systemd-container
systemd-debugsource
systemd-help
systemd-debuginfo
systemd-udev-compat
Red Hat OpenShift Serverless
Windows Container Support for Red Hat OpenShift
OpenShift Virtualization
Cloud Pak for Security (CP4S)
Red Hat OpenShift Jaeger
Red Hat Enterprise Linux for IBM z Systems
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux Server - TUS
openEuler
Fedora
Web Terminal

How to mitigate CVE-2020-13776

Install update from vendor's website.

systemd - update to 245.7
Red Hat OpenShift Serverless - update to 1.16.0
Cloud Pak for Security (CP4S) - update to 1.8.0.0
Red Hat OpenShift Jaeger - addressed in versions 1.17.9, 1.20.4
Windows Container Support for Red Hat OpenShift - update to 2.0.1
systemd (Red Hat package) - addressed in versions 239-31.el8_2.7, 239-45.el8
Web Terminal - update to 1.3
OpenShift Virtualization - update to 4.8.0
systemd-udev - update to 239-31.0.1
systemd-tests - update to 239-31.0.1
systemd-pam - update to 239-31.0.1
systemd-libs - update to 239-31.0.1
systemd-journal-remote - update to 239-31.0.1
systemd-devel - update to 239-31.0.1
systemd-container - update to 239-31.0.1
systemd - update to 239-31.0.1
systemd-debugsource - update to 243-50
systemd-help - update to 243-50
systemd-udev - update to 243-50
systemd-debuginfo - update to 243-50
systemd-udev-compat - update to 243-50
systemd-libs - update to 243-50
systemd-journal-remote - update to 243-50
systemd-devel - update to 243-50
systemd-container - update to 243-50
systemd - update to 243-50
systemd - update to 245.7-1.fc32

External References

Related Security Bulletins