CVE-2021-33910 PUBLISHED

basic/unit-name.c in systemd prior to 246.15, 247.8, 248.5, and 249.1 has a Memory Allocation with an Excessive Size Value (involving strdupa and alloca for a pathname controlled by a local attacker) that results in an operating system crash.

EPSS 0.08% · 23.4th percentile

Risk Scores

EPSS Score
0.08%
23.4th percentile

Affected Products

VendorProductVersions
Ubuntu:20.04:LTSsystemd245.4-4ubuntu3.7, 245.4-4ubuntu3.6, 245.4-4ubuntu3.5
Ubuntu:Pro:16.04:LTSsystemd229-4ubuntu5, 229-4ubuntu6, 229-4ubuntu7
Ubuntu:18.04:LTSsystemd237-3ubuntu10.19, 237-3ubuntu10.20, 237-3ubuntu10.21

Timeline

References

Open in Interactive Console →