iTnews
  • Home
  • News
  • Technology
  • Security

Linux systemd bug allows denial of service attacks

By Juha Saarinen on Jul 21, 2021 12:09PM
Linux systemd bug allows denial of service attacks

Old Linux bugs come back to bite users.

Security researchers have discovered bugs when parsing long file system paths in Linux-based operating systems that can be used to crash them and for local privilege escalation to the root superuser.

The first affects the systemd software which acts as a system and service manager, running as the first OS process (PID 1).

Security vendor Qualys said a vulnerability was introduced into systemd version 220 in April 2015, which allows an unprivileged user to panic the Linux kernel, and cause a denial of service attack.

Long mount point paths can crash systemd with a segmentation fault which, in turn, takes down the entire operating system.

"As a result, if the total path length of this mountpoint exceeds 8MB (the default RLIMIT_STACK), then systemd crashes with a segmentation fault that also crashes the entire operating system (a kernel panic, because systemd is the 'global init', PID 1)," Qualys said in its technical analysis of the bug.

There are no mitigations for the CVE-2021-33910 systemd bug, and Qualys recommends that administrators apply patches from the Linux distributions immediately.

A related bug, CVE-2021-33909 or "Sequoia", allows local, non-privileged users to elevate their accounts to the root superuser one, by abusing long folder paths.

The attack requires users to create, mount and delete a deep directory structure with a total path length exceeding 1 gigabyte.

There are mitigations against the Sequoia bug which was introduced into the Linux kernel in 2014, but they do not completely address the vulnerability and Qualys advises users to apply patches as soon as possible.

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:
linuxqualyssecuritysequoiasoftwaresystemd

Partner Content

Accenture and Google Cloud team up to create a loveable, Australian-first, renewable energy product
Promoted Content Accenture and Google Cloud team up to create a loveable, Australian-first, renewable energy product
Security "mindset shift" needed to protect organisations
Promoted Content Security "mindset shift" needed to protect organisations
Avoiding CAPEX by making on-premise IT more cloud-like
Promoted Content Avoiding CAPEX by making on-premise IT more cloud-like
"We're seeing some good policy put in place, but that's the exception"
Partner Content "We're seeing some good policy put in place, but that's the exception"

Sponsored Whitepapers

Extracting the value of data using Unified Observability
Extracting the value of data using Unified Observability
Planning before the breach: You can’t protect what you can’t see
Planning before the breach: You can’t protect what you can’t see
Beyond FTP: Securing and Managing File Transfers
Beyond FTP: Securing and Managing File Transfers
NextGen Security Operations: A Roadmap for the Future
NextGen Security Operations: A Roadmap for the Future
Video: Watch Juniper talk about its Aston Martin partnership
Video: Watch Juniper talk about its Aston Martin partnership

Events

  • Micro Focus Information Management & Governance (IM&G) Forum 2022
  • CRN Channel Meets: CyberSecurity Live Event
  • IoT Insights: Secure By Design for manufacturing
  • Cyber Security for Government Summit
By Juha Saarinen
Jul 21 2021
12:09PM
0 Comments

Related Articles

  • Patch now against Linux 'Nimbuspwn' root priv-esc bugs
  • Serious Linux privilege escalation bug lay hidden for 12 years
  • The Good Guys pauses facial recognition trial
  • Collins Foods puts IT focus on security controls, cloud services
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Qantas calls time on IBM, Fujitsu in tech modernisation

Qantas calls time on IBM, Fujitsu in tech modernisation

Service NSW hits digital services goal two years early

Service NSW hits digital services goal two years early

NBN Co taking orders for 'non-premises' connections

NBN Co taking orders for 'non-premises' connections

Australian scientists build world's first quantum computer IC

Australian scientists build world's first quantum computer IC

Digital Nation

The security threat of quantum computing
The security threat of quantum computing
IBM global chief data officer on the rise of the number crunchers
IBM global chief data officer on the rise of the number crunchers
Crypto experts optimistic about future of Bitcoin: Block
Crypto experts optimistic about future of Bitcoin: Block
Integrity, ethics and board decisions in the digital age
Integrity, ethics and board decisions in the digital age
COVER STORY: Operationalising net zero through the power of IoT
COVER STORY: Operationalising net zero through the power of IoT
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.