Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-3997

Опубликовано: 23 авг. 2022
Источник: debian
EPSS Низкий

Описание

A flaw was found in systemd. An uncontrolled recursion in systemd-tmpfiles may lead to a denial of service at boot time when too many nested directories are created in /tmp.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
systemdfixed250.2-1package
systemdfixed247.3-7bullseyepackage
systemdignoredbusterpackage
systemdignoredstretchpackage

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=2024639

  • https://github.com/systemd/systemd/pull/22070

  • https://www.openwall.com/lists/oss-security/2022/01/10/2

  • Exploitable after (but present before): https://github.com/systemd/systemd/commit/e5358401b5df8d395e99815b7a69b8424887472c (v242-rc1)

  • PoC still crashes on jessie/215-17+deb8u14

  • Prerequisite/Preparation: https://github.com/systemd/systemd/commit/3bac86abfa1b1720180840ffb9d06b3d54841c11

  • Prerequisite/Preparation: https://github.com/systemd/systemd/commit/84ced330020c0bae57bd4628f1f44eec91304e69

  • Fixed by: https://github.com/systemd/systemd/commit/5b1cf7a9be37e20133c0208005274ce4a5b5c6a1

EPSS

Процентиль: 12%
0.00041
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 3 года назад

A flaw was found in systemd. An uncontrolled recursion in systemd-tmpfiles may lead to a denial of service at boot time when too many nested directories are created in /tmp.

CVSS3: 5.5
redhat
больше 3 лет назад

A flaw was found in systemd. An uncontrolled recursion in systemd-tmpfiles may lead to a denial of service at boot time when too many nested directories are created in /tmp.

CVSS3: 5.5
nvd
почти 3 года назад

A flaw was found in systemd. An uncontrolled recursion in systemd-tmpfiles may lead to a denial of service at boot time when too many nested directories are created in /tmp.

CVSS3: 5.5
msrc
почти 3 года назад

Описание отсутствует

suse-cvrf
больше 3 лет назад

Security update for systemd

EPSS

Процентиль: 12%
0.00041
Низкий