CVE-2018-1049
moderate-risk
Published 2018-02-16
In systemd prior to 234 a race condition exists between .mount and .automount units such that automount requests from kernel may not be serviced by systemd resulting in kernel holding the mountpoint and any processes that try to use said mount will hang. A race condition like this may lead to denial of service, until mount points are unmounted.
Do I need to act?
-
0.51% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
5
CVSS 5.9/10
Medium
NETWORK
/ HIGH complexity
Affected Products (17)
Affected Vendors
References (10)
Third Party Advisory
http://www.securitytracker.com/id/1041520
Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:0260
Issue Tracking
https://bugzilla.redhat.com/show_bug.cgi?id=1534701
Third Party Advisory
https://usn.ubuntu.com/3558-1/
Third Party Advisory
http://www.securitytracker.com/id/1041520
Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:0260
Issue Tracking
https://bugzilla.redhat.com/show_bug.cgi?id=1534701
Third Party Advisory
https://usn.ubuntu.com/3558-1/
39
/ 100
moderate-risk
Severity
18/34 · Moderate
Exploitability
2/34 · Minimal
Exposure
19/34 · Moderate