Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2020-13776
NixOS vulnerability analysis and mitigation

Overview

systemd through v245 contains a vulnerability that mishandles numerical usernames such as ones composed of decimal digits or 0x followed by hex digits, as demonstrated by use of root privileges when privileges of the 0x0 user account were intended. This issue exists because of an incomplete fix for CVE-2017-1000082 (CVE Mitre, NVD).

Technical details

The vulnerability occurs in the user name parsing functionality where systemd incorrectly handles usernames that begin with decimal digits or '0x' followed by hexadecimal digits. When the base argument is 0 or 16, the string can be interpreted as a hexadecimal number, leading to potential privilege escalation. The issue was identified in the systemd/src/basic/user-util.c file, specifically in the parsing functions that handle user identifiers (GitHub Issue).

Impact

Successful exploitation of this vulnerability could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). The vulnerability has been assigned a CVSS v3.1 score of 9.8 (CRITICAL) with a vector of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H (NetApp Advisory).

Exploitability

The vulnerability requires an administrator to create a systemd service unit with a numerical username or a username starting with 0x as a User= value, and that particular userid would need to exist on the system. This scenario is considered unlikely, which has led some vendors to assign it a lower priority (Ubuntu Security).

Mitigation and workarounds

The primary mitigation is to avoid creating systemd service units with User= values set to numerical usernames or usernames that start with 0x. The issue was fixed in systemd version 246-rc1 through two commits: 156a5fd and 6495ced. Some distributions have backported these fixes to their stable releases (Debian Tracker).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-91782LOW1.9
  • NixOS logoNixOS
  • gcc10-binutils
NoYesSep 15, 2026
CVE-2026-91781LOW1.9
  • NixOS logoNixOS
  • binutils
NoYesSep 15, 2026
CVE-2026-91780LOW1.9
  • NixOS logoNixOS
  • binutils
NoNoSep 15, 2026
CVE-2026-91779LOW1.9
  • NixOS logoNixOS
  • binutils
NoNoSep 15, 2026
CVE-2026-90831LOW1.9
  • NixOS logoNixOS
  • gcc-toolset-16-binutils.src
NoYesSep 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management