systemd, a system and service manager, (as PID 1) hits an assert and freezes execution when an unprivileged IPC API call is made with spurious data. On version v249 and older the effect is not an assert, but stack overwriting, with the attacker controlled content. From version v250 and newer this is not possible as the safety check causes an assert instead. This IPC call was added in v239, so versions older than that are not affected. Versions 260-rc1, 259.2, 258.5, and 257.11 contain patches. No known workarounds are available.
{
"binaries": [
{
"binary_name": "libnss-myhostname",
"binary_version": "245.4-4ubuntu3.24+esm3"
},
{
"binary_name": "libnss-mymachines",
"binary_version": "245.4-4ubuntu3.24+esm3"
},
{
"binary_name": "libnss-resolve",
"binary_version": "245.4-4ubuntu3.24+esm3"
},
{
"binary_name": "libnss-systemd",
"binary_version": "245.4-4ubuntu3.24+esm3"
},
{
"binary_name": "libpam-systemd",
"binary_version": "245.4-4ubuntu3.24+esm3"
},
{
"binary_name": "libsystemd0",
"binary_version": "245.4-4ubuntu3.24+esm3"
},
{
"binary_name": "libudev1",
"binary_version": "245.4-4ubuntu3.24+esm3"
},
{
"binary_name": "systemd",
"binary_version": "245.4-4ubuntu3.24+esm3"
},
{
"binary_name": "systemd-container",
"binary_version": "245.4-4ubuntu3.24+esm3"
},
{
"binary_name": "systemd-coredump",
"binary_version": "245.4-4ubuntu3.24+esm3"
},
{
"binary_name": "systemd-journal-remote",
"binary_version": "245.4-4ubuntu3.24+esm3"
},
{
"binary_name": "systemd-sysv",
"binary_version": "245.4-4ubuntu3.24+esm3"
},
{
"binary_name": "systemd-tests",
"binary_version": "245.4-4ubuntu3.24+esm3"
},
{
"binary_name": "systemd-timesyncd",
"binary_version": "245.4-4ubuntu3.24+esm3"
},
{
"binary_name": "udev",
"binary_version": "245.4-4ubuntu3.24+esm3"
}
],
"availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro"
}
{
"binaries": [
{
"binary_name": "libnss-myhostname",
"binary_version": "249.11-0ubuntu3.19"
},
{
"binary_name": "libnss-mymachines",
"binary_version": "249.11-0ubuntu3.19"
},
{
"binary_name": "libnss-resolve",
"binary_version": "249.11-0ubuntu3.19"
},
{
"binary_name": "libnss-systemd",
"binary_version": "249.11-0ubuntu3.19"
},
{
"binary_name": "libpam-systemd",
"binary_version": "249.11-0ubuntu3.19"
},
{
"binary_name": "libsystemd0",
"binary_version": "249.11-0ubuntu3.19"
},
{
"binary_name": "libudev1",
"binary_version": "249.11-0ubuntu3.19"
},
{
"binary_name": "systemd",
"binary_version": "249.11-0ubuntu3.19"
},
{
"binary_name": "systemd-container",
"binary_version": "249.11-0ubuntu3.19"
},
{
"binary_name": "systemd-coredump",
"binary_version": "249.11-0ubuntu3.19"
},
{
"binary_name": "systemd-journal-remote",
"binary_version": "249.11-0ubuntu3.19"
},
{
"binary_name": "systemd-oomd",
"binary_version": "249.11-0ubuntu3.19"
},
{
"binary_name": "systemd-repart",
"binary_version": "249.11-0ubuntu3.19"
},
{
"binary_name": "systemd-standalone-sysusers",
"binary_version": "249.11-0ubuntu3.19"
},
{
"binary_name": "systemd-standalone-tmpfiles",
"binary_version": "249.11-0ubuntu3.19"
},
{
"binary_name": "systemd-sysv",
"binary_version": "249.11-0ubuntu3.19"
},
{
"binary_name": "systemd-tests",
"binary_version": "249.11-0ubuntu3.19"
},
{
"binary_name": "systemd-timesyncd",
"binary_version": "249.11-0ubuntu3.19"
},
{
"binary_name": "udev",
"binary_version": "249.11-0ubuntu3.19"
}
],
"availability": "No subscription required"
}
{
"binaries": [
{
"binary_name": "libnss-myhostname",
"binary_version": "255.4-1ubuntu8.14"
},
{
"binary_name": "libnss-mymachines",
"binary_version": "255.4-1ubuntu8.14"
},
{
"binary_name": "libnss-resolve",
"binary_version": "255.4-1ubuntu8.14"
},
{
"binary_name": "libnss-systemd",
"binary_version": "255.4-1ubuntu8.14"
},
{
"binary_name": "libpam-systemd",
"binary_version": "255.4-1ubuntu8.14"
},
{
"binary_name": "libsystemd-shared",
"binary_version": "255.4-1ubuntu8.14"
},
{
"binary_name": "libsystemd0",
"binary_version": "255.4-1ubuntu8.14"
},
{
"binary_name": "libudev1",
"binary_version": "255.4-1ubuntu8.14"
},
{
"binary_name": "systemd",
"binary_version": "255.4-1ubuntu8.14"
},
{
"binary_name": "systemd-boot",
"binary_version": "255.4-1ubuntu8.14"
},
{
"binary_name": "systemd-boot-efi",
"binary_version": "255.4-1ubuntu8.14"
},
{
"binary_name": "systemd-container",
"binary_version": "255.4-1ubuntu8.14"
},
{
"binary_name": "systemd-coredump",
"binary_version": "255.4-1ubuntu8.14"
},
{
"binary_name": "systemd-homed",
"binary_version": "255.4-1ubuntu8.14"
},
{
"binary_name": "systemd-journal-remote",
"binary_version": "255.4-1ubuntu8.14"
},
{
"binary_name": "systemd-oomd",
"binary_version": "255.4-1ubuntu8.14"
},
{
"binary_name": "systemd-resolved",
"binary_version": "255.4-1ubuntu8.14"
},
{
"binary_name": "systemd-standalone-sysusers",
"binary_version": "255.4-1ubuntu8.14"
},
{
"binary_name": "systemd-standalone-tmpfiles",
"binary_version": "255.4-1ubuntu8.14"
},
{
"binary_name": "systemd-sysv",
"binary_version": "255.4-1ubuntu8.14"
},
{
"binary_name": "systemd-tests",
"binary_version": "255.4-1ubuntu8.14"
},
{
"binary_name": "systemd-timesyncd",
"binary_version": "255.4-1ubuntu8.14"
},
{
"binary_name": "systemd-ukify",
"binary_version": "255.4-1ubuntu8.14"
},
{
"binary_name": "systemd-userdbd",
"binary_version": "255.4-1ubuntu8.14"
},
{
"binary_name": "udev",
"binary_version": "255.4-1ubuntu8.14"
}
],
"availability": "No subscription required"
}
{
"binaries": [
{
"binary_name": "libnss-myhostname",
"binary_version": "257.9-0ubuntu2.3"
},
{
"binary_name": "libnss-mymachines",
"binary_version": "257.9-0ubuntu2.3"
},
{
"binary_name": "libnss-resolve",
"binary_version": "257.9-0ubuntu2.3"
},
{
"binary_name": "libnss-systemd",
"binary_version": "257.9-0ubuntu2.3"
},
{
"binary_name": "libpam-systemd",
"binary_version": "257.9-0ubuntu2.3"
},
{
"binary_name": "libsystemd-shared",
"binary_version": "257.9-0ubuntu2.3"
},
{
"binary_name": "libsystemd0",
"binary_version": "257.9-0ubuntu2.3"
},
{
"binary_name": "libudev1",
"binary_version": "257.9-0ubuntu2.3"
},
{
"binary_name": "systemd",
"binary_version": "257.9-0ubuntu2.3"
},
{
"binary_name": "systemd-boot",
"binary_version": "257.9-0ubuntu2.3"
},
{
"binary_name": "systemd-boot-efi",
"binary_version": "257.9-0ubuntu2.3"
},
{
"binary_name": "systemd-boot-tools",
"binary_version": "257.9-0ubuntu2.3"
},
{
"binary_name": "systemd-container",
"binary_version": "257.9-0ubuntu2.3"
},
{
"binary_name": "systemd-coredump",
"binary_version": "257.9-0ubuntu2.3"
},
{
"binary_name": "systemd-cryptsetup",
"binary_version": "257.9-0ubuntu2.3"
},
{
"binary_name": "systemd-homed",
"binary_version": "257.9-0ubuntu2.3"
},
{
"binary_name": "systemd-journal-remote",
"binary_version": "257.9-0ubuntu2.3"
},
{
"binary_name": "systemd-oomd",
"binary_version": "257.9-0ubuntu2.3"
},
{
"binary_name": "systemd-repart",
"binary_version": "257.9-0ubuntu2.3"
},
{
"binary_name": "systemd-resolved",
"binary_version": "257.9-0ubuntu2.3"
},
{
"binary_name": "systemd-standalone-shutdown",
"binary_version": "257.9-0ubuntu2.3"
},
{
"binary_name": "systemd-standalone-sysusers",
"binary_version": "257.9-0ubuntu2.3"
},
{
"binary_name": "systemd-standalone-tmpfiles",
"binary_version": "257.9-0ubuntu2.3"
},
{
"binary_name": "systemd-sysv",
"binary_version": "257.9-0ubuntu2.3"
},
{
"binary_name": "systemd-tests",
"binary_version": "257.9-0ubuntu2.3"
},
{
"binary_name": "systemd-timesyncd",
"binary_version": "257.9-0ubuntu2.3"
},
{
"binary_name": "systemd-ukify",
"binary_version": "257.9-0ubuntu2.3"
},
{
"binary_name": "systemd-userdbd",
"binary_version": "257.9-0ubuntu2.3"
},
{
"binary_name": "udev",
"binary_version": "257.9-0ubuntu2.3"
}
],
"availability": "No subscription required"
}