Wind River Support Network

HomeDefectsLIN1018-3533
Fixed

LIN1018-3533 : Security Advisory - systemd - CVE-2019-3815

Created: Feb 14, 2019    Updated: Aug 4, 2019
Resolved Date: Aug 4, 2019
Found In Version: unknown
Severity: Standard
Applicable for: Wind River Linux LTS 18
Component/s: Userspace

Description

A memory leak was discovered in the backport of fixes for CVE-2018-16864 in Red Hat Enterprise Linux. Function dispatch_message_real() in journald-server.c does not free the memory allocated by set_iovec_field_free() to store the `_CMDLINE=` entry. A local attacker may use this flaw to make systemd-journald crash. This issue only affects versions shipped with Red Hat Enterprise since v219-62.2.

https://nvd.nist.gov/vuln/detail/CVE-2019-3815

CVEs


Live chat
Online