Skip to content

systemd CVE-2021-33910

High
tjkirch published GHSA-x6h2-jvgx-gwph Jul 23, 2021

Package

systemd (bottlerocket)

Affected versions

< 1.1.4

Patched versions

1.1.4

Description

A flaw was found in systemd where an unverified input to alloca in the function unit_name_path_escape allows a local attacker, who is able to mount a filesystem on a very long path, to crash systemd and the whole system by allocating a very large space in the stack.

Severity

High

CVE ID

CVE-2021-33910

Weaknesses

No CWEs