CVE-2019-3843: Canonical Ubuntu Linux

High severity, CVSS 7.8. EPSS: 0.9% chance of exploitation in the next 30 days.

It was discovered that a systemd service that uses DynamicUser property can create a SUID/SGID binary that would be allowed to run as the transient service UID/GID even after the service is terminated. A local attacker may use this flaw to access resources that will be owned by a potentially different service in the future, when the UID/GID will be recycled.

Affected products

  • Canonical Ubuntu Linux: version 16.04 only; version 18.04 only; version 19.10 only
  • Fedoraproject Fedora: version 30 only
  • Netapp CN1610 Firmware: affected versions not specified
  • Netapp Hci Management Node: affected versions not specified
  • Netapp Snapprotect: affected versions not specified
  • Netapp Solidfire: affected versions not specified
  • Systemd Project Systemd: before 242 (fixed in 242)

Published 2019-04-26. Last modified 2026-06-17.