CVE Vulnerabilities

CVE-2019-3843

Incorrect Privilege Assignment

Published: Apr 26, 2019 | Modified: Nov 21, 2024
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
4.6 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
4.5 MODERATE
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
Ubuntu
LOW

It was discovered that a systemd service that uses DynamicUser property can create a SUID/SGID binary that would be allowed to run as the transient service UID/GID even after the service is terminated. A local attacker may use this flaw to access resources that will be owned by a potentially different service in the future, when the UID/GID will be recycled.

Weakness

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Systemd Systemd_project * 242 (excluding)
Systemd Ubuntu bionic *
Systemd Ubuntu cosmic *
Systemd Ubuntu disco *
Red Hat Enterprise Linux 8 RedHat systemd-0:239-29.el8 *

Potential Mitigations

References