basic/unit-name.c in systemd prior to 246.15, 247.8, 248.5, and 249.1 has a Memory Allocation with an Excessive Size Value (involving strdupa and alloca for a pathname controlled by a local attacker) that results in an operating system crash.
2021-07-20T19:15:09.783
2025-06-09T16:15:32.380
Modified
CVSSv3.1: 5.5 (MEDIUM)
AV:L/AC:L/Au:N/C:N/I:N/A:C
3.9
6.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | systemd_project | systemd | < 246.15 | Yes |
Application | systemd_project | systemd | < 247.8 | Yes |
Application | systemd_project | systemd | < 248.5 | Yes |
Application | systemd_project | systemd | < 249.1 | Yes |
Operating System | fedoraproject | fedora | 33 | Yes |
Operating System | fedoraproject | fedora | 34 | Yes |
Operating System | debian | debian_linux | 10.0 | Yes |
Application | netapp | hci_management_node | - | Yes |
Application | netapp | solidfire | - | Yes |