Description
A memory leak was discovered in the backport of fixes for CVE-2018-16864 in Red Hat Enterprise Linux. Function dispatch_message_real() in journald-server.c does not free the memory allocated by set_iovec_field_free() to store the `_CMDLINE=` entry. A local attacker may use this flaw to make systemd-journald crash. This issue only affects versions shipped with Red Hat Enterprise since v219-62.2.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1711-1 | systemd security update |
EUVD |
EUVD-2019-13438 | A memory leak was discovered in the backport of fixes for CVE-2018-16864 in Red Hat Enterprise Linux. Function dispatch_message_real() in journald-server.c does not free the memory allocated by set_iovec_field_free() to store the `_CMDLINE=` entry. A local attacker may use this flaw to make systemd-journald crash. This issue only affects versions shipped with Red Hat Enterprise since v219-62.2. |
References
History
No history.
Subscriptions
Debian
Subscribe
Debian Linux
Subscribe
Redhat
Subscribe
Enterprise Linux
Subscribe
Enterprise Linux Desktop
Subscribe
Enterprise Linux Server
Subscribe
Enterprise Linux Server Aus
Subscribe
Enterprise Linux Server Eus
Subscribe
Enterprise Linux Workstation
Subscribe
Openshift Container Platform
Subscribe
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-04T19:19:18.592Z
Reserved: 2019-01-03T00:00:00.000Z
Link: CVE-2019-3815
No data.
Status : Modified
Published: 2019-01-28T15:29:00.307
Modified: 2024-11-21T04:42:35.960
Link: CVE-2019-3815
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
EUVD