CVE-2019-3843: Canonical Ubuntu Linux
High severity, CVSS 7.8. EPSS: 0.9% chance of exploitation in the next 30 days.
It was discovered that a systemd service that uses DynamicUser property can create a SUID/SGID binary that would be allowed to run as the transient service UID/GID even after the service is terminated. A local attacker may use this flaw to access resources that will be owned by a potentially different service in the future, when the UID/GID will be recycled.
Affected products
- Canonical Ubuntu Linux: version 16.04 only; version 18.04 only; version 19.10 only
- Fedoraproject Fedora: version 30 only
- Netapp CN1610 Firmware: affected versions not specified
- Netapp Hci Management Node: affected versions not specified
- Netapp Snapprotect: affected versions not specified
- Netapp Solidfire: affected versions not specified
- Systemd Project Systemd: before 242 (fixed in 242)
Published 2019-04-26. Last modified 2026-06-17.