CVE-2021-3997
Published: 10 January 2022
A flaw was found in systemd. An uncontrolled recursion in systemd-tmpfiles may lead to a denial of service at boot time when too many nested directories are created in /tmp.
Notes
Author | Note |
---|---|
alexmurray | This vulnerability does not appear to be exploitable for systemd versions before v242 (ie before commit e535840) and onwards hence this is not possible to be exploited on Ubuntu 18.04 LTS and earlier. |
Priority
Status
Package | Release | Status |
---|---|---|
systemd Launchpad, Ubuntu, Debian |
bionic |
Ignored
(cannot be exploited)
|
focal |
Released
(245.4-4ubuntu3.15)
|
|
hirsute |
Released
(247.3-3ubuntu3.7)
|
|
impish |
Released
(248.3-1ubuntu8.2)
|
|
trusty |
Ignored
(cannot be exploited)
|
|
upstream |
Needs triage
|
|
xenial |
Ignored
(cannot be exploited)
|
Severity score breakdown
Parameter | Value |
---|---|
Base score | 5.5 |
Attack vector | Local |
Attack complexity | Low |
Privileges required | Low |
User interaction | None |
Scope | Unchanged |
Confidentiality | None |
Integrity impact | None |
Availability impact | High |
Vector | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |