CVE-2018-15686: Canonical Ubuntu Linux
High severity, CVSS 7.8. EPSS: 2.3% chance of exploitation in the next 30 days.
A vulnerability in unit_deserialize of systemd allows an attacker to supply arbitrary state across systemd re-execution via NotifyAccess. This can be used to improperly influence systemd execution and possibly lead to root privilege escalation. Affected releases are systemd versions up to and including 239.
Affected products
- Canonical Ubuntu Linux: version 16.04 only; version 18.04 only; version 18.10 only
- Debian Debian Linux: version 8.0 only
- Oracle Communications Cloud Native Core Network Function Cloud Native Environment: version 1.4.0 only
- Systemd Project Systemd: up to and including 239
Published 2018-10-26. Last modified 2026-06-17.