HIGH✓ PATCH🇵🇱 Wersja polska

CVE-2019-3844

CVSS 7.8v3.1pub. 2019-04-26upd. 2024-11-21

It was discovered that a systemd service that uses DynamicUser property can get new privileges through the execution of SUID binaries, which would allow to create binaries owned by the service transient group with the setgid bit set. A local attacker may use this flaw to access resources that will be owned by a potentially different service in the future, when the GID will be recycled.

CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • Canonical Ubuntu

    OS
    Canonical
    16.0418.0419.10
  • Netapp Cn1610

    HW
    Netapp
    all versions
  • Netapp Cn1610 Firmware

    OS
    Netapp
    all versions
  • Netapp Hci Management Node

    APP
    Netapp
    all versions
  • Netapp Snapprotect

    APP
    Netapp
    all versions
  • Netapp Solidfire

    APP
    Netapp
    all versions
  • Systemd Project Systemd

    APP
    Systemd Project
    < 242
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2025-32463CRITICAL9.3⚠ KEVPL ✓same product

Sudo: eskalacja uprawnień do root poprzez opcję --chroot (CVE-2025-32463)

CVE-2022-0543CRITICAL10.0⚠ KEVPL ✓same product

Redis – ucieczka z Lua sandbox umożliwiająca zdalne wykonanie kodu (RCE)

CVE-2020-11651CRITICAL9.8⚠ KEVPL ✓same product

SaltStack Salt: nieautoryzowany dostęp do metod salt-master umożliwiający RCE

CVE-2020-7247CRITICAL9.8⚠ KEVPL ✓same product

RCE jako root w OpenSMTPD przez command injection w polu MAIL FROM

CVE-2019-16928CRITICAL9.8⚠ KEVPL ✓same product

RCE w Exim — heap-based buffer overflow w obsłudze komendy EHLO