CVE-2020-1712: Debian Linux

High severity, CVSS 7.8. EPSS: 0.5% chance of exploitation in the next 30 days.

A heap use-after-free vulnerability was found in systemd before version v245-rc1, where asynchronous Polkit queries are performed while handling dbus messages. A local unprivileged attacker can abuse this flaw to crash systemd services or potentially execute code and elevate their privileges, by sending specially crafted dbus messages.

Affected products

  • Debian Debian Linux: version 9.0 only
  • Red Hat Ceph Storage: version 4.0 only
  • Red Hat Discovery: affected versions not specified
  • Red Hat Enterprise Linux: version 8.0 only
  • Red Hat Migration Toolkit: version 1.0 only
  • Red Hat Openshift Container Platform: version 4.0 only
  • Systemd Project Systemd: up to and including 244

Published 2020-03-31. Last modified 2026-06-17.