Name | CVE-2021-33910 |
Description | basic/unit-name.c in systemd prior to 246.15, 247.8, 248.5, and 249.1 has a Memory Allocation with an Excessive Size Value (involving strdupa and alloca for a pathname controlled by a local attacker) that results in an operating system crash. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
References | DLA-2715-1, DSA-4942-1 |
The table below lists information on source packages.
Source Package | Release | Version | Status |
---|---|---|---|
systemd (PTS) | bullseye | 247.3-7+deb11u5 | fixed |
bullseye (security) | 247.3-7+deb11u6 | fixed | |
bookworm | 252.30-1~deb12u2 | fixed | |
trixie | 256.6-1 | fixed | |
sid | 256.7-1 | fixed |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|---|---|---|---|---|---|
systemd | source | stretch | 232-25+deb9u13 | DLA-2715-1 | ||
systemd | source | buster | 241-7~deb10u8 | DSA-4942-1 | ||
systemd | source | (unstable) | 247.3-6 |
https://www.qualys.com/2021/07/20/cve-2021-33910/denial-of-service-systemd.txt
Introduced by: https://github.com/systemd/systemd/commit/7410616cd9dbbec97cf98d75324da5cda2b2f7a2 (v220)
Fixed by: https://github.com/systemd/systemd/commit/441e0115646d54f080e5c3bb0ba477c892861ab9
Fixed by: https://github.com/systemd/systemd/commit/4e2544c30bfb95e7cb4d1551ba066b1a56520ad6 (comment fix)
https://github.com/systemd/systemd/pull/20256