Lucene search

K
ubuntuUbuntuUSN-5395-1
HistoryApr 28, 2022 - 12:00 a.m.

networkd-dispatcher vulnerabilities

2022-04-2800:00:00
ubuntu.com
214
ubuntu
networkd-dispatcher
cve-2022-29799
cve-2022-29800
systemd-networkd
privilege escalation
race condition
arbitrary code

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

AI Score

5.9

Confidence

High

EPSS

0.001

Percentile

25.9%

Releases

  • Ubuntu 22.04 LTS
  • Ubuntu 21.10
  • Ubuntu 20.04 LTS
  • Ubuntu 18.04 ESM

Packages

  • networkd-dispatcher - Dispatcher service for systemd-networkd connection status changes

Details

It was discovered that networkd-dispatcher incorrectly handled internal
scripts. A local attacker could possibly use this issue to cause a race
condition, escalate privileges and execute arbitrary code.
(CVE-2022-29799, CVE-2022-29800)

OSVersionArchitecturePackageVersionFilename
Ubuntu22.04noarchnetworkd-dispatcher< 2.1-2ubuntu0.22.04.1UNKNOWN
Ubuntu21.10noarchnetworkd-dispatcher< 2.1-2ubuntu0.21.10.1UNKNOWN
Ubuntu20.04noarchnetworkd-dispatcher< 2.1-2~ubuntu20.04.2UNKNOWN
Ubuntu18.04noarchnetworkd-dispatcher< 1.7-0ubuntu3.4UNKNOWN

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

AI Score

5.9

Confidence

High

EPSS

0.001

Percentile

25.9%