Denial of Service Vulnerability in Systemd Affecting Linux Distributions
CVE-2021-3997

5.5MEDIUM

Key Information:

Status
Vendor
CVE Published:
23 August 2022

What is CVE-2021-3997?

A vulnerability exists in systemd, specifically in the systemd-tmpfiles component, which could result in denial of service during system boot. This flaw leads to uncontrolled recursion when an excessive number of nested directories are created in the /tmp directory, potentially hanging the system or causing it to fail to boot properly. Users of affected versions of systemd are advised to apply patches to mitigate this issue.

Affected Version(s)

systemd Fixed in v251-rc1

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.