Lucene search

K
ubuntuUbuntuUSN-5226-1
HistoryJan 13, 2022 - 12:00 a.m.

systemd vulnerability

2022-01-1300:00:00
ubuntu.com
162
ubuntu
systemd
vulnerability
recursion
local attacker

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

AI Score

5.9

Confidence

High

EPSS

0.001

Percentile

23.4%

Releases

  • Ubuntu 21.10
  • Ubuntu 21.04
  • Ubuntu 20.04 LTS

Packages

  • systemd - system and service manager

Details

It was discovered that systemd-tmpfiles employed uncontrolled recursion
when removing deeply nested directory hierarchies. A local attacker could
exploit this to cause systemd-tmpfiles to crash or have other unspecified
impacts.

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

AI Score

5.9

Confidence

High

EPSS

0.001

Percentile

23.4%