CVE-2019-15718: Fedoraproject Fedora

Medium severity, CVSS 4.4. EPSS: 0.5% chance of exploitation in the next 30 days.

In systemd 240, bus_open_system_watch_bind_with_description in shared/bus-util.c (as used by systemd-resolved to connect to the system D-Bus instance), calls sd_bus_set_trusted, which disables access controls for incoming D-Bus messages. An unprivileged user can exploit this by executing D-Bus methods that should be restricted to privileged users, in order to change the system's DNS resolver settings.

Affected products

  • Fedoraproject Fedora: version 29 only; version 30 only; version 31 only
  • Red Hat Enterprise Linux: version 8.0 only
  • Red Hat Enterprise Linux Eus: version 8.1 only; version 8.2 only; version 8.4 only
  • Red Hat Enterprise Linux For IBM Z Systems 8 s390x: any version
  • Red Hat Enterprise Linux For IBM Z Systems Eus: version 8.1 only; version 8.2 only; version 8.4 only
  • Red Hat Enterprise Linux For IBM Z Systems Eus s390x: version 8.1 only; version 8.2 only
  • Red Hat Enterprise Linux For Power Little Endian: version 8.0 only
  • Red Hat Enterprise Linux For Power Little Endian Eus: version 8.1 only; version 8.2 only; version 8.4 only
  • Red Hat Enterprise Linux Server Aus: version 8.2 only; version 8.4 only
  • Red Hat Enterprise Linux Server For Power Little Endian Update Services For SAP Solutions: version 8.1 only; version 8.2 only; version 8.4 only
  • Red Hat Enterprise Linux Server Tus: version 8.2 only; version 8.4 only
  • Red Hat Enterprise Linux Server Update Services For SAP Solutions: version 8.1 only; version 8.2 only; version 8.4 only
  • Red Hat Openshift Container Platform: version 4.1 only
  • Systemd Project Systemd: version 240 only

Published 2019-09-04. Last modified 2026-06-17.