« List of all CVEs

CVE-2018-16866

Published: 1/11/2019 Last updated: 6/9/2025 Reserved: 9/11/2018

An out of bounds read was discovered in systemd-journald in the way it parses log messages that terminate with a colon ':'. A local attacker can use this flaw to disclose process memory data. Versions from v221 to v239 are vulnerable.

CNA assigner: redhat (53f830b8-0a3f-465b-8143-3b8a9948e749) Requested by: n/a

Metrics

Version Score Severity Vector String
3.0 4.3 Medium CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Opam packages affected (2)

conf-libudev ocaml-systemd

Products affected (1)

Product Vendor Version
systemd The systemd Project Android-11

References (28)