CVE-2021-33910

basic/unit-name.c in systemd prior to 246.15, 247.8, 248.5, and 249.1 has a Memory Allocation with an Excessive Size Value (involving strdupa and alloca for a pathname controlled by a local attacker) that results in an operating system crash.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.5 MEDIUM
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 33%
VendorProductVersion
systemd_projectsystemd
𝑥
< 246.15
systemd_projectsystemd
247 ≤
𝑥
< 247.8
systemd_projectsystemd
248 ≤
𝑥
< 248.5
systemd_projectsystemd
249 ≤
𝑥
< 249.1
debiandebian_linux
10.0
netapphci_management_node
-
netappsolidfire
-
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
systemd
bullseye
247.3-7+deb11u5
fixed
bullseye (security)
247.3-7+deb11u6
fixed
bookworm
252.30-1~deb12u2
fixed
sid
256.7-3
fixed
trixie
256.7-3
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
systemd
jammy
Fixed 248.3-1ubuntu3
released
impish
Fixed 248.3-1ubuntu3
released
hirsute
Fixed 247.3-3ubuntu3.4
released
groovy
Fixed 246.6-1ubuntu1.7
released
focal
Fixed 245.4-4ubuntu3.10
released
bionic
Fixed 237-3ubuntu10.49
released
xenial
Fixed 229-4ubuntu21.31+esm1
released
trusty
not-affected
References