CVE-2021-33910

Description

basic/unit-name.c in systemd prior to 246.15, 247.8, 248.5, and 249.1 has a Memory Allocation with an Excessive Size Value (involving strdupa and alloca for a pathname controlled by a local attacker) that results in an operating system crash.

Risk Information

Base Score
5.5
MODERATE
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
0.079

Associated Vulnerability

VulnerabilityOS Platform
SUSE-SU-2021:2405-1(SUSE Linux Enterprise Server 12-SP5 ) libsystemd0-228-157.30.1.x86_64.rpmLinux
SUSE-SU-2021:2405-1(SUSE Linux Enterprise Server 12-SP5 ) libsystemd0-32bit-228-157.30.1.x86_64.rpmLinux
SUSE-SU-2021:2405-1(SUSE Linux Enterprise Server 12-SP5 ) libsystemd0-debuginfo-228-157.30.1.x86_64.rpmLinux
SUSE-SU-2021:2405-1(SUSE Linux Enterprise Server 12-SP5 ) libsystemd0-debuginfo-32bit-228-157.30.1.x86_64.rpmLinux
SUSE-SU-2021:2405-1(SUSE Linux Enterprise Server 12-SP5 ) libudev-devel-228-157.30.1.x86_64.rpmLinux
SUSE-SU-2021:2405-1(SUSE Linux Enterprise Server 12-SP5 ) libudev1-228-157.30.1.x86_64.rpmLinux
SUSE-SU-2021:2405-1(SUSE Linux Enterprise Server 12-SP5 ) libudev1-32bit-228-157.30.1.x86_64.rpmLinux
SUSE-SU-2021:2405-1(SUSE Linux Enterprise Server 12-SP5 ) libudev1-debuginfo-228-157.30.1.x86_64.rpmLinux
SUSE-SU-2021:2405-1(SUSE Linux Enterprise Server 12-SP5 ) libudev1-debuginfo-32bit-228-157.30.1.x86_64.rpmLinux
SUSE-SU-2021:2405-1(SUSE Linux Enterprise Server 12-SP5 ) systemd-228-157.30.1.x86_64.rpmLinux
SUSE-SU-2021:2405-1(SUSE Linux Enterprise Server 12-SP5 ) systemd-32bit-228-157.30.1.x86_64.rpmLinux
SUSE-SU-2021:2405-1(SUSE Linux Enterprise Server 12-SP5 ) systemd-bash-completion-228-157.30.1.noarch.rpmLinux
SUSE-SU-2021:2405-1(SUSE Linux Enterprise Server 12-SP5 ) systemd-debuginfo-228-157.30.1.x86_64.rpmLinux
SUSE-SU-2021:2405-1(SUSE Linux Enterprise Server 12-SP5 ) systemd-debuginfo-32bit-228-157.30.1.x86_64.rpmLinux
SUSE-SU-2021:2405-1(SUSE Linux Enterprise Server 12-SP5 ) systemd-debugsource-228-157.30.1.x86_64.rpmLinux
SUSE-SU-2021:2405-1(SUSE Linux Enterprise Server 12-SP5 ) systemd-devel-228-157.30.1.x86_64.rpmLinux
SUSE-SU-2021:2405-1(SUSE Linux Enterprise Server 12-SP5 ) systemd-sysvinit-228-157.30.1.x86_64.rpmLinux
SUSE-SU-2021:2405-1(SUSE Linux Enterprise Server 12-SP5 ) udev-228-157.30.1.x86_64.rpmLinux
SUSE-SU-2021:2405-1(SUSE Linux Enterprise Server 12-SP5 ) udev-debuginfo-228-157.30.1.x86_64.rpmLinux
systemd security update(DSA-4942-1) systemd_241-7~deb10u8_i386.debLinux
systemd security update(DSA-4942-1) systemd_241-7~deb10u8_amd64.debLinux
system and service manager (USN-5013-1) systemd_237-3ubuntu10.49_i386.debLinux
system and service manager (USN-5013-1) systemd_237-3ubuntu10.49_amd64.debLinux
system and service manager (USN-5013-1) systemd_246.6-1ubuntu1.7_i386.debLinux
system and service manager (USN-5013-1) systemd_246.6-1ubuntu1.7_amd64.debLinux
system and service manager (USN-5013-1) systemd_247.3-3ubuntu3.4_i386.debLinux
system and service manager (USN-5013-1) systemd_247.3-3ubuntu3.4_amd64.debLinux
system and service manager (USN-5013-1) systemd_245.4-4ubuntu3.10_i386.debLinux
system and service manager (USN-5013-1) systemd_245.4-4ubuntu3.10_amd64.debLinux
Systemd update (ELSA-2021-2717) systemd-239-45.0.2.el8_4.2.i686.rpmLinux
Systemd update (ELSA-2021-2717) systemd-239-45.0.2.el8_4.2.x86_64.rpmLinux
Systemd-container update (ELSA-2021-2717) systemd-container-239-45.0.2.el8_4.2.i686.rpmLinux
Systemd-container update (ELSA-2021-2717) systemd-container-239-45.0.2.el8_4.2.x86_64.rpmLinux
Systemd-devel update (ELSA-2021-2717) systemd-devel-239-45.0.2.el8_4.2.i686.rpmLinux
Systemd-devel update (ELSA-2021-2717) systemd-devel-239-45.0.2.el8_4.2.x86_64.rpmLinux
Systemd-journal-remote update (ELSA-2021-2717) systemd-journal-remote-239-45.0.2.el8_4.2.x86_64.rpmLinux
Systemd-libs update (ELSA-2021-2717) systemd-libs-239-45.0.2.el8_4.2.i686.rpmLinux
Systemd-libs update (ELSA-2021-2717) systemd-libs-239-45.0.2.el8_4.2.x86_64.rpmLinux
Systemd-pam update (ELSA-2021-2717) systemd-pam-239-45.0.2.el8_4.2.x86_64.rpmLinux
Systemd-tests update (ELSA-2021-2717) systemd-tests-239-45.0.2.el8_4.2.x86_64.rpmLinux
Systemd-udev update (ELSA-2021-2717) systemd-udev-239-45.0.2.el8_4.2.x86_64.rpmLinux
(RHSA-2021:2717) systemd security update systemd-239-45.el8_4.2.i686.rpmLinux
(RHSA-2021:2717) systemd security update systemd-239-45.el8_4.2.x86_64.rpmLinux
(RHSA-2021:2717) systemd security update systemd-container-239-45.el8_4.2.i686.rpmLinux
(RHSA-2021:2717) systemd security update systemd-container-239-45.el8_4.2.x86_64.rpmLinux
(RHSA-2021:2717) systemd security update systemd-debugsource-239-45.el8_4.2.i686.rpmLinux
(RHSA-2021:2717) systemd security update systemd-debugsource-239-45.el8_4.2.x86_64.rpmLinux
(RHSA-2021:2717) systemd security update systemd-devel-239-45.el8_4.2.i686.rpmLinux
(RHSA-2021:2717) systemd security update systemd-devel-239-45.el8_4.2.x86_64.rpmLinux
(RHSA-2021:2717) systemd security update systemd-journal-remote-239-45.el8_4.2.x86_64.rpmLinux
(RHSA-2021:2717) systemd security update systemd-libs-239-45.el8_4.2.i686.rpmLinux
(RHSA-2021:2717) systemd security update systemd-libs-239-45.el8_4.2.x86_64.rpmLinux
(RHSA-2021:2717) systemd security update systemd-pam-239-45.el8_4.2.x86_64.rpmLinux
(RHSA-2021:2717) systemd security update systemd-tests-239-45.el8_4.2.x86_64.rpmLinux
(RHSA-2021:2717) systemd security update systemd-udev-239-45.el8_4.2.x86_64.rpmLinux
SUSE-SU-2021:3611-1(SUSE Linux Enterprise Server 12-SP5 ) libsystemd0-228-157.33.1.x86_64.rpmLinux
SUSE-SU-2021:3611-1(SUSE Linux Enterprise Server 12-SP5 ) libsystemd0-32bit-228-157.33.1.x86_64.rpmLinux
SUSE-SU-2021:3611-1(SUSE Linux Enterprise Server 12-SP5 ) libsystemd0-debuginfo-228-157.33.1.x86_64.rpmLinux
SUSE-SU-2021:3611-1(SUSE Linux Enterprise Server 12-SP5 ) libsystemd0-debuginfo-32bit-228-157.33.1.x86_64.rpmLinux
SUSE-SU-2021:3611-1(SUSE Linux Enterprise Server 12-SP5 ) libudev-devel-228-157.33.1.x86_64.rpmLinux
SUSE-SU-2021:3611-1(SUSE Linux Enterprise Server 12-SP5 ) libudev1-228-157.33.1.x86_64.rpmLinux
SUSE-SU-2021:3611-1(SUSE Linux Enterprise Server 12-SP5 ) libudev1-32bit-228-157.33.1.x86_64.rpmLinux
SUSE-SU-2021:3611-1(SUSE Linux Enterprise Server 12-SP5 ) libudev1-debuginfo-228-157.33.1.x86_64.rpmLinux
SUSE-SU-2021:3611-1(SUSE Linux Enterprise Server 12-SP5 ) libudev1-debuginfo-32bit-228-157.33.1.x86_64.rpmLinux
SUSE-SU-2021:3611-1(SUSE Linux Enterprise Server 12-SP5 ) systemd-228-157.33.1.x86_64.rpmLinux
SUSE-SU-2021:3611-1(SUSE Linux Enterprise Server 12-SP5 ) systemd-32bit-228-157.33.1.x86_64.rpmLinux
SUSE-SU-2021:3611-1(SUSE Linux Enterprise Server 12-SP5 ) systemd-bash-completion-228-157.33.1.noarch.rpmLinux
SUSE-SU-2021:3611-1(SUSE Linux Enterprise Server 12-SP5 ) systemd-debuginfo-228-157.33.1.x86_64.rpmLinux
SUSE-SU-2021:3611-1(SUSE Linux Enterprise Server 12-SP5 ) systemd-debuginfo-32bit-228-157.33.1.x86_64.rpmLinux
SUSE-SU-2021:3611-1(SUSE Linux Enterprise Server 12-SP5 ) systemd-debugsource-228-157.33.1.x86_64.rpmLinux
SUSE-SU-2021:3611-1(SUSE Linux Enterprise Server 12-SP5 ) systemd-devel-228-157.33.1.x86_64.rpmLinux
SUSE-SU-2021:3611-1(SUSE Linux Enterprise Server 12-SP5 ) systemd-sysvinit-228-157.33.1.x86_64.rpmLinux
SUSE-SU-2021:3611-1(SUSE Linux Enterprise Server 12-SP5 ) udev-228-157.33.1.x86_64.rpmLinux
SUSE-SU-2021:3611-1(SUSE Linux Enterprise Server 12-SP5 ) udev-debuginfo-228-157.33.1.x86_64.rpmLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234