CVE-2020-1712: Debian Linux
High severity, CVSS 7.8. EPSS: 0.5% chance of exploitation in the next 30 days.
A heap use-after-free vulnerability was found in systemd before version v245-rc1, where asynchronous Polkit queries are performed while handling dbus messages. A local unprivileged attacker can abuse this flaw to crash systemd services or potentially execute code and elevate their privileges, by sending specially crafted dbus messages.
Affected products
- Debian Debian Linux: version 9.0 only
- Red Hat Ceph Storage: version 4.0 only
- Red Hat Discovery: affected versions not specified
- Red Hat Enterprise Linux: version 8.0 only
- Red Hat Migration Toolkit: version 1.0 only
- Red Hat Openshift Container Platform: version 4.0 only
- Systemd Project Systemd: up to and including 244
Published 2020-03-31. Last modified 2026-06-17.