« List of all CVEs

CVE-2018-6954

Published: 2/13/2018 Last updated: 6/9/2025 Reserved: 2/13/2018

systemd-tmpfiles in systemd through 237 mishandles symlinks present in non-terminal path components, which allows local users to obtain ownership of arbitrary files via vectors involving creation of a directory and a file under that directory, and later replacing that directory with a symlink. This occurs even if the fs.protected_symlinks sysctl is turned on.

CNA assigner: mitre (8254265b-2729-46b6-b9e3-3dfca2d5bfca) Requested by: n/a

Metrics

Version Score Severity Vector String
3.1 7.8 High CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Opam packages affected (2)

conf-libudev ocaml-systemd

Products affected (1)

Product Vendor Version
n/a n/a <= 5.4.*

References (12)