Nasty Linux systemd security bug revealed

General News

Summary

Successful exploitation of this newest vulnerability enables any unprivileged user to cause a denial of service via a kernel panic. It works by enabling attackers to misuse the alloca() function in a way that would result in memory corruption. This, in turn, allows a hacker to crash systemd and hence the entire operating system. Practically speaking, this can be done by a local attacker mounting a filesystem on a very long path. The good news is that Red Hat Product Security and systemds developers have immediately patched the hole.

Classifications

industries
Information Technology
applications
General BI

AskAI Classifications

Labels
Operating Systems Infrastructure Software DevOps Tools

Linked Companies

Canonical, Ltd.
$50M to $100M
Qualys, Inc.
$500M to $1B
Red Hat
$1B+