Bug 1534701 (CVE-2018-1049) - CVE-2018-1049 systemd: automount: access to automounted volumes can lock up
Summary: CVE-2018-1049 systemd: automount: access to automounted volumes can lock up
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2018-1049
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1535130 1535134 1535135 1535462 1535463
Blocks: 1534699
TreeView+ depends on / blocked
 
Reported: 2018-01-15 18:30 UTC by Pedro Sampaio
Modified: 2021-03-11 16:55 UTC (History)
10 users (show)

Fixed In Version: systemd-234
Doc Type: If docs needed, set a value
Doc Text:
A race condition was found in systemd. This could result in automount requests not being serviced and processes using them could hang, causing denial of service.
Clone Of:
Environment:
Last Closed: 2018-02-19 04:50:23 UTC
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2018:0260 0 normal SHIPPED_LIVE Moderate: systemd security update 2018-01-31 23:54:36 UTC

Description Pedro Sampaio 2018-01-15 18:30:11 UTC
In systemd prior to 234 a race exists between .mount and .automount units such that automount requests from kernel may not be serviced by systemd resulting in kernel holding the mountpoint and any processes that try to use said mount will hang. A race like this may lead to denial of service, until mount points are unmounted.

References:

https://bugs.launchpad.net/ubuntu/+source/systemd/+bug/1709649

https://github.com/coreos/bugs/issues/1630

http://seclists.org/oss-sec/2018/q1/80

An upstream issue:

https://github.com/systemd/systemd/pull/5916

An upstream patch:

https://github.com/systemd/systemd/commit/e7d54bf58789545a9eb0b3964233defa0b007318

Comment 2 Vladis Dronov 2018-01-16 16:53:57 UTC
Created systemd tracking bugs for this issue:

Affects: fedora-all [bug 1535130]

Comment 5 errata-xmlrpc 2018-01-31 18:49:37 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7

Via RHSA-2018:0260 https://access.redhat.com/errata/RHSA-2018:0260


Note You need to log in before you can comment on or make changes to this bug.