CVE-2018-6954

Severity CVSS v4.0:
Pending analysis
Type:
CWE-59 Link Following
Publication date:
13/02/2018
Last modified:
09/06/2025

Description

systemd-tmpfiles in systemd through 237 mishandles symlinks present in non-terminal path components, which allows local users to obtain ownership of arbitrary files via vectors involving creation of a directory and a file under that directory, and later replacing that directory with a symlink. This occurs even if the fs.protected_symlinks sysctl is turned on.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:systemd_project:systemd:*:*:*:*:*:*:*:* 237 (including)
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:18.10:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:leap:42.3:*:*:*:*:*:*:*