Back to search
CVE-2018-6954
Published: Feb 13, 2018
Modified: Jun 9, 2025
PUBLISHED
Description
systemd-tmpfiles in systemd through 237 mishandles symlinks present in non-terminal path components, which allows local users to obtain ownership of arbitrary files via vectors involving creation of a directory and a file under that directory, and later replacing that directory with a symlink. This occurs even if the fs.protected_symlinks sysctl is turned on.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
USN-3816-2
vendor-advisory
x_refsource_UBUNTU
https://github.com/systemd/systemd/issues/7986
x_refsource_MISC
USN-3816-1
vendor-advisory
x_refsource_UBUNTU
openSUSE-SU-2019:1450
vendor-advisory
x_refsource_SUSE
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now