CVE-2019-3843

Aliases:DEBIAN-CVE-2019-3843CGA-42wp-4j3g-h55xCGA-6g4j-87mq-95w9CGA-9ph2-mvg4-588vCGA-cg4m-2533-fjm5CGA-g25q-2vjj-6rjgCGA-gpc8-2h6q-fgw9CGA-m3v5-9cvg-cq6gCGA-vc89-3rjx-hvcgCGA-vhjj-fc9w-qc3rCGA-x79j-2668-m7ph
Modified
Published: 26 Apr 2019, 20:27
Last modified:09 Jun 2025, 15:49

Vulnerability Summary

Overall Risk (default)
medium
41/100
CVSS Score
7.8 HIGH
v3.1 (nvd)
EPSS Score
0.94% LOW
1% probability +0.81%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

26 Apr 2019, 20:27
Published
Vulnerability first disclosed
09 Jun 2025, 15:49
Last Modified
Vulnerability information updated

Description

It was discovered that a systemd service that uses DynamicUser property can create a SUID/SGID binary that would be allowed to run as the transient service UID/GID even after the service is terminated. A local attacker may use this flaw to access resources that will be owned by a potentially different service in the future, when the UID/GID will be recycled.

CVSS Metrics

  • v3.1HIGHScore: 7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • v3.0MEDIUMScore: 4.5CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
  • v2.0MEDIUMScore: 4.6AV:L/AC:L/Au:N/C:P/I:P/A:P

EPSS Trends

Current EPSS score: 0.94% Percentile: 59%

Techniques & Countermeasures

  • CWE-266Incorrect Privilege Assignment

    A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

  • CWE-269Improper Privilege Management

    The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Systems

  • chainguardpy3-systemd

    < 0

  • chainguardpy3.10-systemd

    < 0

  • chainguardpy3.11-systemd

    < 0

  • chainguardpy3.12-systemd

    < 0

  • chainguardpy3.13-systemd

    < 0

  • canonicalubuntu_linux

    16.04 | 18.04 | 19.10

  • debiansystemd

    < 242-4 | < 242-4 | < 242-4 | < 242-4

  • fedoraprojectfedora

    30

  • [freedesktop.org]systemd

    242

  • netappcn1610_firmware

    na

  • netapphci_management_node

    na

  • netappsnapprotect

    na

  • netappsolidfire

    na

  • systemd_projectsystemd

    < 242

References (8)