MEDIUM · 5.5

CVE-2019-6454

An issue was discovered in sd-bus in systemd 239. bus_process_object() in libsystemd/sd-bus/bus-objects.c allocates a variable-length stack buffer for temporarily storing the object path of incoming D...

Vulnerability Description

An issue was discovered in sd-bus in systemd 239. bus_process_object() in libsystemd/sd-bus/bus-objects.c allocates a variable-length stack buffer for temporarily storing the object path of incoming D-Bus messages. An unprivileged local user can exploit this by sending a specially crafted message to PID1, causing the stack pointer to jump over the stack guard pages into an unmapped memory region and trigger a denial of service (systemd PID1 crash and kernel panic).

CVSS Score

5.5

MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
Systemd ProjectSystemd239
OpensuseLeap15.0
NetappActive Iq Performance Analytics Services-
DebianDebian Linux8.0
FedoraprojectFedora29
CanonicalUbuntu Linux16.04
RedhatEnterprise Linux8.0
RedhatEnterprise Linux Compute Node Eus7.5
RedhatEnterprise Linux Desktop7.0
RedhatEnterprise Linux Eus7.4
RedhatEnterprise Linux For Ibm Z Systems Eus7.4
RedhatEnterprise Linux For Power Big Endian Eus7.4
RedhatEnterprise Linux For Power Little Endian8.0
RedhatEnterprise Linux For Power Little Endian Eus7.4
RedhatEnterprise Linux Server7.0
RedhatEnterprise Linux Server Aus7.3
RedhatEnterprise Linux Server Eus7.6
RedhatEnterprise Linux Server For Power Little Endian Update Services For Sap Solutions7.3
RedhatEnterprise Linux Server Tus7.3
RedhatEnterprise Linux Server Update Services For Sap Solutions7.3

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-6454?

CVE-2019-6454 is a vulnerability with a CVSS score of 5.5 (MEDIUM). An issue was discovered in sd-bus in systemd 239. bus_process_object() in libsystemd/sd-bus/bus-objects.c allocates a variable-length stack buffer for temporarily storing the object path of incoming D...

How severe is CVE-2019-6454?

CVE-2019-6454 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-6454?

Check the references section above for vendor advisories and patch information. Affected products include: Systemd Project Systemd, Opensuse Leap, Netapp Active Iq Performance Analytics Services, Debian Debian Linux, Fedoraproject Fedora.