Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2018-1049: access to automounted volumes can lock up

In systemd prior to 234 a race condition exists between .mount and .automount units such that automount requests from kernel may not be serviced by systemd resulting in kernel holding the mountpoint and any processes that try to use said mount will hang. A race condition like this may lead to denial of service, until mount points are unmounted.

CVE
#vulnerability#ubuntu#linux#red_hat#dos#git

Bug 1534701 (CVE-2018-1049) - CVE-2018-1049 systemd: automount: access to automounted volumes can lock up

Summary: CVE-2018-1049 systemd: automount: access to automounted volumes can lock up

Keywords:

Status:

CLOSED ERRATA

Alias:

CVE-2018-1049

Product:

Security Response

Classification:

Other

Component:

vulnerability

Sub Component:

Version:

unspecified

Hardware:

All

OS:

Linux

Priority:

medium

Severity:

medium

Target Milestone:

Assignee:

Red Hat Product Security

QA Contact:

Docs Contact:

URL:

Whiteboard:

Depends On:

1535130 1535134 1535135 1535462 1535463

Blocks:

1534699

TreeView+

depends on / blocked

Reported:

2018-01-15 18:30 UTC by Pedro Sampaio

Modified:

2021-03-11 16:55 UTC (History)

CC List:

10 users (show)

Fixed In Version:

systemd-234

Doc Type:

If docs needed, set a value

Doc Text:

A race condition was found in systemd. This could result in automount requests not being serviced and processes using them could hang, causing denial of service.

Clone Of:

Environment:

Last Closed:

2018-02-19 04:50:23 UTC

Attachments

(Terms of Use)

Add an attachment (proposed patch, testcase, etc.)

Links

System

ID

Private

Priority

Status

Summary

Last Updated

Red Hat Product Errata

RHSA-2018:0260

0

normal

SHIPPED_LIVE

Moderate: systemd security update

2018-01-31 23:54:36 UTC

Description Pedro Sampaio 2018-01-15 18:30:11 UTC

In systemd prior to 234 a race exists between .mount and .automount units such that automount requests from kernel may not be serviced by systemd resulting in kernel holding the mountpoint and any processes that try to use said mount will hang. A race like this may lead to denial of service, until mount points are unmounted.

References:

https://bugs.launchpad.net/ubuntu/+source/systemd/+bug/1709649

https://github.com/coreos/bugs/issues/1630

http://seclists.org/oss-sec/2018/q1/80

An upstream issue:

https://github.com/systemd/systemd/pull/5916

An upstream patch:

https://github.com/systemd/systemd/commit/e7d54bf58789545a9eb0b3964233defa0b007318

Comment 2 Vladis Dronov 2018-01-16 16:53:57 UTC

Created systemd tracking bugs for this issue:

Affects: fedora-all [bug 1535130]

Comment 5 errata-xmlrpc 2018-01-31 18:49:37 UTC

This issue has been addressed in the following products:

Red Hat Enterprise Linux 7

Via RHSA-2018:0260 https://access.redhat.com/errata/RHSA-2018:0260

Note You need to log in before you can comment on or make changes to this bug.

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907