CVE-2019-3844
Summary
| CVE | CVE-2019-3844 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-04-26 21:29:00 UTC |
| Updated | 2023-11-07 03:10:00 UTC |
| Description | It was discovered that a systemd service that uses DynamicUser property can get new privileges through the execution of SUID binaries, which would allow to create binaries owned by the service transient group with the setgid bit set. A local attacker may use this flaw to access resources that will be owned by a potentially different service in the future, when the GID will be recycled. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| 1684610 – (CVE-2019-3844) CVE-2019-3844 systemd: services with DynamicUser can get new privileges and create SGID binaries |
CONFIRM |
bugzilla.redhat.com |
Issue Tracking, Patch, Third Party Advisory |
| systemd CVE-2019-3844 Local Privilege Escalation Vulnerability |
BID |
www.securityfocus.com |
Third Party Advisory, VDB Entry |
| [bookkeeper-issues] 20210628 [GitHub] [bookkeeper] padma81 opened a new issue #2746: Security Vulnerabilities in CentOS 7 image, Upgrade image to CentOS 8 |
|
lists.apache.org |
|
| Pony Mail! |
MLIST |
lists.apache.org |
|
| USN-4269-1: systemd vulnerabilities | Ubuntu security notices |
UBUNTU |
usn.ubuntu.com |
Third Party Advisory |
| Pony Mail! |
MLIST |
lists.apache.org |
|
| [bookkeeper-issues] 20210629 [GitHub] [bookkeeper] padma81 opened a new issue #2746: Security Vulnerabilities in CentOS 7 image, Upgrade image to CentOS 8 |
|
lists.apache.org |
|
| May 2019 Systemd Vulnerabilities in NetApp Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 900080 CBL-Mariner Linux Security Update for systemd 239
- 903186 Common Base Linux Mariner (CBL-Mariner) Security Update for systemd (1794)