Three vulnerabilities disovered in systemd

Jan. 14, 2019

Three (CVE-2018-16864, CVE-2018-16865, CVE-2018-16866) vulnerabilities discovered in systemd-journald. First two are memory corruptions (attacker-controlled alloca()s), the third one is an information leak (an out-of-bounds read). According to researchers all systemd-based Linux distributions are vulnerable, but SUSE Linux Enterprise 15, openSUSE Leap 15.0, and Fedora 28 and 29 are not exploitable because their user space is compiled with GCC's -fstack-clash-protection.

UPDATE: An update for systemd is now available for Red Hat Enterprise Linux 7.