
Cloud Vulnerability DB
A community-led vulnerabilities database
systemd through v245 contains a vulnerability that mishandles numerical usernames such as ones composed of decimal digits or 0x followed by hex digits, as demonstrated by use of root privileges when privileges of the 0x0 user account were intended. This issue exists because of an incomplete fix for CVE-2017-1000082 (CVE Mitre, NVD).
The vulnerability occurs in the user name parsing functionality where systemd incorrectly handles usernames that begin with decimal digits or '0x' followed by hexadecimal digits. When the base argument is 0 or 16, the string can be interpreted as a hexadecimal number, leading to potential privilege escalation. The issue was identified in the systemd/src/basic/user-util.c file, specifically in the parsing functions that handle user identifiers (GitHub Issue).
Successful exploitation of this vulnerability could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). The vulnerability has been assigned a CVSS v3.1 score of 9.8 (CRITICAL) with a vector of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H (NetApp Advisory).
The vulnerability requires an administrator to create a systemd service unit with a numerical username or a username starting with 0x as a User= value, and that particular userid would need to exist on the system. This scenario is considered unlikely, which has led some vendors to assign it a lower priority (Ubuntu Security).
The primary mitigation is to avoid creating systemd service units with User= values set to numerical usernames or usernames that start with 0x. The issue was fixed in systemd version 246-rc1 through two commits: 156a5fd and 6495ced. Some distributions have backported these fixes to their stable releases (Debian Tracker).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."