Rapid7 Vulnerability & Exploit Database

Oracle Linux: CVE-2018-1049: ELSA-2018-0260: systemd security update (MODERATE)

Free InsightVM Trial No Credit Card Necessary
2024 Attack Intel Report Latest research by Rapid7 Labs
Back to Search

Oracle Linux: CVE-2018-1049: ELSA-2018-0260: systemd security update (MODERATE)

Severity
5
CVSS
(AV:A/AC:L/Au:M/C:N/I:N/A:C)
Published
05/09/2017
Created
07/25/2018
Added
02/01/2018
Modified
07/22/2024

Description

In systemd prior to 234 a race condition exists between .mount and .automount units such that automount requests from kernel may not be serviced by systemd resulting in kernel holding the mountpoint and any processes that try to use said mount will hang. A race condition like this may lead to denial of service, until mount points are unmounted. A race condition was found in systemd. This could result in automount requests not being serviced and processes using them could hang, causing denial of service.

Solution(s)

  • oracle-linux-upgrade-libgudev1
  • oracle-linux-upgrade-systemd
  • oracle-linux-upgrade-systemd-devel
  • oracle-linux-upgrade-systemd-journal-gateway
  • oracle-linux-upgrade-systemd-libs
  • oracle-linux-upgrade-systemd-networkd
  • oracle-linux-upgrade-systemd-python
  • oracle-linux-upgrade-systemd-resolved
  • oracle-linux-upgrade-systemd-sysv

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;