Predictable from Observable State in systemd - CVE-2020-13529

 

Predictable from Observable State in systemd - CVE-2020-13529

Published: April 26, 2021


Vulnerability identifier: #VU52596
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-13529
CWE-ID: CWE-341
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to reconfigure the target device.

The vulnerability exists due to usage of predictable Transactions Identifiers when processing DHCP ACK packets. A remote attacker on the same network can forge the FORCERENEW and DHCP ACK packets to reconfigure the systemd’s DHCP client settings.


Affected software

systemd
NetworkManager (Red Hat package)
systemd (Ubuntu package)
systemd-devel
systemd-container
systemd-udev-compat
systemd-journal-remote
systemd-debugsource
systemd-libs
systemd-udev
systemd-debuginfo
systemd-help
libsystemd0-32bit-debuginfo
systemd-32bit-debuginfo
systemd-32bit
libudev1-32bit-debuginfo
libudev1-32bit
libsystemd0
libsystemd0-debuginfo
libudev-devel
libudev1
libudev1-debuginfo
systemd-container-debuginfo
systemd-coredump
systemd-coredump-debuginfo
libsystemd0-32bit
systemd-doc
systemd-journal-remote-debuginfo
systemd-sysvinit
udev
udev-debuginfo
systemd-lang
Gentoo Linux
Arch Linux
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for IBM z Systems
SUSE Linux Enterprise Module for Basesystem
Ubuntu
openEuler
Fedora
cflinuxfs3

How to mitigate CVE-2020-13529

Install updates from vendor's website.

systemd - update to 248
cflinuxfs3 - update to 0.250.0
NetworkManager (Red Hat package) - update to 1.32.10-4.el8
systemd (Ubuntu package) - addressed in versions 237-3ubuntu10.49, 245.4-4ubuntu3.10, 246.6-1ubuntu1.7, 247.3-3ubuntu3.4, 2294ubuntu21.31+esm1
systemd-devel - update to 243-43
systemd - update to 243-43
systemd-container - update to 243-43
systemd-udev-compat - update to 243-43
systemd-journal-remote - update to 243-43
systemd-debugsource - update to 243-43
systemd-libs - update to 243-43
systemd-udev - update to 243-43
systemd-debuginfo - update to 243-43
systemd-help - update to 243-43
systemd - update to 246.15-1.fc33
libsystemd0-32bit-debuginfo - update to 246.15-7.11.1
systemd-32bit-debuginfo - update to 246.15-7.11.1
systemd-32bit - update to 246.15-7.11.1
libudev1-32bit-debuginfo - update to 246.15-7.11.1
libudev1-32bit - update to 246.15-7.11.1
systemd-debugsource - update to 246.15-7.11.1
libsystemd0 - update to 246.15-7.11.1
libsystemd0-debuginfo - update to 246.15-7.11.1
libudev-devel - update to 246.15-7.11.1
libudev1 - update to 246.15-7.11.1
libudev1-debuginfo - update to 246.15-7.11.1
systemd - update to 246.15-7.11.1
systemd-container - update to 246.15-7.11.1
systemd-container-debuginfo - update to 246.15-7.11.1
systemd-coredump - update to 246.15-7.11.1
systemd-coredump-debuginfo - update to 246.15-7.11.1
systemd-debuginfo - update to 246.15-7.11.1
libsystemd0-32bit - update to 246.15-7.11.1
systemd-devel - update to 246.15-7.11.1
systemd-doc - update to 246.15-7.11.1
systemd-journal-remote - update to 246.15-7.11.1
systemd-journal-remote-debuginfo - update to 246.15-7.11.1
systemd-sysvinit - update to 246.15-7.11.1
udev - update to 246.15-7.11.1
udev-debuginfo - update to 246.15-7.11.1
systemd-lang - update to 246.15-7.11.1

External References

Related Security Bulletins