CVE-2020-1712

A heap use-after-free vulnerability was found in systemd before version v245-rc1, where asynchronous Polkit queries are performed while handling dbus messages. A local unprivileged attacker can abuse this flaw to crash systemd services or potentially execute code and elevate their privileges, by sending specially crafted dbus messages.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
redhatCNA
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 28%
VendorProductVersion
systemd_projectsystemd
𝑥
≤ 244
redhatceph_storage
4.0
redhatdiscovery
-
redhatmigration_toolkit
1.0
redhatopenshift_container_platform
4.0
redhatenterprise_linux
8.0
debiandebian_linux
9.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
systemd
bullseye
247.3-7+deb11u5
fixed
jessie
not-affected
bullseye (security)
247.3-7+deb11u6
fixed
bookworm
252.30-1~deb12u2
fixed
sid
256.7-3
fixed
trixie
256.7-3
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
systemd
noble
Fixed 244.1-0ubuntu3
released
mantic
Fixed 244.1-0ubuntu3
released
lunar
Fixed 244.1-0ubuntu3
released
kinetic
Fixed 244.1-0ubuntu3
released
jammy
Fixed 244.1-0ubuntu3
released
impish
Fixed 244.1-0ubuntu3
released
hirsute
Fixed 244.1-0ubuntu3
released
groovy
Fixed 244.1-0ubuntu3
released
focal
Fixed 244.1-0ubuntu3
released
eoan
Fixed 242-7ubuntu3.6
released
bionic
Fixed 237-3ubuntu10.38
released
xenial
Fixed 229-4ubuntu21.27
released
trusty
needed