Vulnerability Database

289,599

Total vulnerabilities in the database

CVE-2019-6454

An issue was discovered in sd-bus in systemd 239. bus_process_object() in libsystemd/sd-bus/bus-objects.c allocates a variable-length stack buffer for temporarily storing the object path of incoming D-Bus messages. An unprivileged local user can exploit this by sending a specially crafted message to PID1, causing the stack pointer to jump over the stack guard pages into an unmapped memory region and trigger a denial of service (systemd PID1 crash and kernel panic).

  • Published: Mar 21, 2019
  • Updated: Apr 13, 2023
  • CVE: CVE-2019-6454
  • Severity: Medium
  • Exploit:

CVSS v3:

  • Severity: Medium
  • Score: 5.5
  • AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CVSS v2:

  • Severity: Low
  • Score: 4.9
  • AV:L/AC:L/Au:N/C:N/I:N/A:C

CWEs:

Software From Fixed in
systemd_project / systemd 239 239.x
opensuse / leap 15.0 15.0.x
debian / debian_linux 8.0 8.0.x
debian / debian_linux 9.0 9.0.x
fedoraproject / fedora 29 29.x
canonical / ubuntu_linux 16.04 16.04.x
canonical / ubuntu_linux 18.04 18.04.x
canonical / ubuntu_linux 18.10 18.10.x
redhat / enterprise_linux_desktop 7.0 7.0.x
redhat / enterprise_linux_workstation 7.0 7.0.x
redhat / enterprise_linux_server 7.0 7.0.x
redhat / enterprise_linux_server_tus 7.3 7.3.x
redhat / enterprise_linux_server_aus 7.3 7.3.x
redhat / enterprise_linux_server_aus 7.4 7.4.x
redhat / enterprise_linux_server_tus 7.4 7.4.x
redhat / enterprise_linux_eus 7.4 7.4.x
redhat / enterprise_linux_eus 7.5 7.5.x
redhat / enterprise_linux_server_tus 7.6 7.6.x
redhat / enterprise_linux_server_eus 7.6 7.6.x
redhat / enterprise_linux_server_aus 7.6 7.6.x
redhat / enterprise_linux 8.0 8.0.x
redhat / enterprise_linux_eus 8.1 8.1.x
redhat / enterprise_linux_eus 8.2 8.2.x
redhat / enterprise_linux_server_tus 8.2 8.2.x
redhat / enterprise_linux_server_aus 8.2 8.2.x
redhat / enterprise_linux_server_tus 8.4 8.4.x
redhat / enterprise_linux_eus 8.4 8.4.x
redhat / enterprise_linux_server_aus 8.4 8.4.x
redhat / enterprise_linux_server_update_services_for_sap_solutions 8.2 8.2.x
redhat / enterprise_linux_server_update_services_for_sap_solutions 8.1 8.1.x
redhat / enterprise_linux_for_power_little_endian_eus 8.2 8.2.x
redhat / enterprise_linux_for_ibm_z_systems_eus 8.2 8.2.x
redhat / enterprise_linux_for_ibm_z_systems_eus 8.1 8.1.x
redhat / enterprise_linux_for_power_little_endian_eus 8.1 8.1.x
redhat / enterprise_linux_for_power_little_endian 8.0 8.0.x
redhat / enterprise_linux_for_ibm_z_systems_eus 8.4 8.4.x
redhat / enterprise_linux_for_power_little_endian_eus 8.4 8.4.x
redhat / enterprise_linux_server_update_services_for_sap_solutions 7.4 7.4.x
redhat / enterprise_linux_server_update_services_for_sap_solutions 7.3 7.3.x
redhat / enterprise_linux_compute_node_eus 7.5 7.5.x
redhat / enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions 7.4 7.4.x
redhat / enterprise_linux_server_update_services_for_sap_solutions 8.0 8.0.x
redhat / enterprise_linux_for_power_little_endian_eus 7.4 7.4.x
redhat / enterprise_linux_for_ibm_z_systems_eus 7.4 7.4.x
redhat / enterprise_linux_for_power_little_endian_eus 7.5 7.5.x
redhat / enterprise_linux_for_power_big_endian_eus 7.4 7.4.x
redhat / enterprise_linux_for_ibm_z_systems_eus 7.5 7.5.x
redhat / enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions 8.0 8.0.x
redhat / enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions 8.1 8.1.x
redhat / enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions 8.2 8.2.x
redhat / enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions 7.3 7.3.x
mcafee / web_gateway 8.0.0 8.1.1
mcafee / web_gateway - 7.7.2.21
mcafee / web_gateway 7.8.0 7.8.2.8