Bug 1534701 (CVE-2018-1049) - CVE-2018-1049 systemd: automount: access to automounted volumes can lock up
Summary: CVE-2018-1049 systemd: automount: access to automounted volumes can lock up
Alias: CVE-2018-1049
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
Whiteboard: impact=moderate,public=20170509,repor...
Keywords: Security
Depends On: 1535130 1535134 1535135 1535462 1535463
Blocks: 1534699
TreeView+ depends on / blocked
Reported: 2018-01-15 18:30 UTC by Pedro Sampaio
Modified: 2019-06-08 22:37 UTC (History)
10 users (show)

A race condition was found in systemd. This could result in automount requests not being serviced and processes using them could hang, causing denial of service.
Clone Of:
Last Closed: 2018-02-19 04:50:23 UTC

Attachments (Terms of Use)

External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2018:0260 normal SHIPPED_LIVE Moderate: systemd security update 2018-01-31 23:54:36 UTC

Description Pedro Sampaio 2018-01-15 18:30:11 UTC
In systemd prior to 234 a race exists between .mount and .automount units such that automount requests from kernel may not be serviced by systemd resulting in kernel holding the mountpoint and any processes that try to use said mount will hang. A race like this may lead to denial of service, until mount points are unmounted.





An upstream issue:


An upstream patch:


Comment 2 Vladis Dronov 2018-01-16 16:53:57 UTC
Created systemd tracking bugs for this issue:

Affects: fedora-all [bug 1535130]

Comment 5 errata-xmlrpc 2018-01-31 18:49:37 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7

Via RHSA-2018:0260 https://access.redhat.com/errata/RHSA-2018:0260

Note You need to log in before you can comment on or make changes to this bug.