CVE-2018-16866: Canonical Ubuntu Linux

Low severity, CVSS 3.3. EPSS: 1.1% chance of exploitation in the next 30 days.

An out of bounds read was discovered in systemd-journald in the way it parses log messages that terminate with a colon ':'. A local attacker can use this flaw to disclose process memory data. Versions from v221 to v239 are vulnerable.

Affected products

  • Canonical Ubuntu Linux: version 16.04 only; version 18.04 only; version 18.10 only
  • Debian Debian Linux: version 9.0 only
  • Netapp Active Iq Performance Analytics Services: affected versions not specified
  • Netapp Element Software: any version
  • Red Hat Enterprise Linux: version 7.6 only
  • Red Hat Enterprise Linux Compute Node Eus: version 7.6 only
  • Red Hat Enterprise Linux Desktop: version 7.0 only
  • Red Hat Enterprise Linux For IBM Z Systems (structure A): version 7_s390x only
  • Red Hat Enterprise Linux For IBM Z Systems Eus: version 7.6 only
  • Red Hat Enterprise Linux For Power Big Endian: version 7.0 only
  • Red Hat Enterprise Linux For Power Big Endian Eus: version 7.6 only
  • Red Hat Enterprise Linux For Power Little Endian: version 7.0 only
  • Red Hat Enterprise Linux For Power Little Endian Eus: version 7.6 only
  • Red Hat Enterprise Linux For Scientific Computing: version 7.0 only
  • Red Hat Enterprise Linux Server: version 7.0 only
  • Red Hat Enterprise Linux Server Aus: version 7.4 only; version 7.6 only
  • Red Hat Enterprise Linux Server For Power Little Endian Update Services For SAP Solutions: version 7.4 only; version 7.6 only
  • Red Hat Enterprise Linux Server Tus: version 7.4 only; version 7.6 only
  • Red Hat Enterprise Linux Server Update Services For SAP Solutions: version 7.4 only; version 7.6 only
  • Red Hat Enterprise Linux Workstation: version 7.0 only
  • Systemd Project Systemd: from 221, up to and including 239

Published 2019-01-11. Last modified 2026-06-17.