CVE-2019-3844: Canonical Ubuntu Linux

High severity, CVSS 7.8. EPSS: 0.9% chance of exploitation in the next 30 days.

It was discovered that a systemd service that uses DynamicUser property can get new privileges through the execution of SUID binaries, which would allow to create binaries owned by the service transient group with the setgid bit set. A local attacker may use this flaw to access resources that will be owned by a potentially different service in the future, when the GID will be recycled.

Affected products

  • Canonical Ubuntu Linux: version 16.04 only; version 18.04 only; version 19.10 only
  • Netapp CN1610 Firmware: affected versions not specified
  • Netapp Hci Management Node: affected versions not specified
  • Netapp Snapprotect: affected versions not specified
  • Netapp Solidfire: affected versions not specified
  • Systemd Project Systemd: before 242 (fixed in 242)

Published 2019-04-26. Last modified 2026-06-17.