It was discovered that a systemd service that uses DynamicUser property can get new privileges through the execution of SUID binaries, which would allow to create binaries owned by the service transient group with the setgid bit set. A local attacker may use this flaw to access resources that will be owned by a potentially different service in the future, when the GID will be recycled.
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HCanonical Ubuntu
OSCanonical16.0418.0419.10Netapp Cn1610
HWNetappall versionsNetapp Cn1610 Firmware
OSNetappall versionsNetapp Hci Management Node
APPNetappall versionsNetapp Snapprotect
APPNetappall versionsNetapp Solidfire
APPNetappall versionsSystemd Project Systemd
APPSystemd Project< 242
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
References
Related vulnerabilities
CVE-2025-32463CRITICAL9.3⚠ KEVPL ✓same product
Sudo: eskalacja uprawnień do root poprzez opcję --chroot (CVE-2025-32463)
CVE-2022-0543CRITICAL10.0⚠ KEVPL ✓same product
Redis – ucieczka z Lua sandbox umożliwiająca zdalne wykonanie kodu (RCE)
CVE-2020-11651CRITICAL9.8⚠ KEVPL ✓same product
SaltStack Salt: nieautoryzowany dostęp do metod salt-master umożliwiający RCE
CVE-2020-7247CRITICAL9.8⚠ KEVPL ✓same product
RCE jako root w OpenSMTPD przez command injection w polu MAIL FROM
CVE-2019-16928CRITICAL9.8⚠ KEVPL ✓same product
RCE w Exim — heap-based buffer overflow w obsłudze komendy EHLO