CVE-2018-6954

HIGH

systemd < 237 - Local Privilege Escalation via Symlink Handling in systemd-tmpfiles

Title source: llm
STIX 2.1

Description

systemd-tmpfiles in systemd through 237 mishandles symlinks present in non-terminal path components, which allows local users to obtain ownership of arbitrary files via vectors involving creation of a directory and a file under that directory, and later replacing that directory with a symlink. This occurs even if the fs.protected_symlinks sysctl is turned on.

References (6)

Core 6
Core References
Third Party Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/3816-2/
Exploit, Issue Tracking, Patch, Third Party Advisory x_refsource_misc
https://github.com/systemd/systemd/issues/7986
Third Party Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/3816-1/
Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00062.html

Scores

CVSS v3 7.8
EPSS 0.0014
EPSS Percentile 34.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-59
Status published
Products (5)
canonical/ubuntu_linux 16.04
canonical/ubuntu_linux 18.04
canonical/ubuntu_linux 18.10
opensuse/leap 42.3
systemd_project/systemd < 237
Published Feb 13, 2018
Tracked Since Feb 18, 2026