Software

OSes

The D in Systemd stands for 'Dammmmit!' A nasty DHCPv6 packet can pwn a vulnerable Linux box

Hole opens up remote-code execution to miscreants – or a crash, if you're lucky


A security bug in Systemd can be exploited over the network to, at best, potentially crash a vulnerable Linux machine, or, at worst, execute malicious code on the box.

The flaw therefore puts Systemd-powered Linux computers – specifically those using systemd-networkd – at risk of remote hijacking: maliciously crafted DHCPv6 packets can try to exploit the programming cockup and arbitrarily change parts of memory in vulnerable systems, leading to potential code execution. This code could install malware, spyware, and other nasties, if successful.

The vulnerability – which was made public this week – sits within the written-from-scratch DHCPv6 client of the open-source Systemd management suite, which is built into various flavors of Linux.

This client is activated automatically if IPv6 support is enabled, and relevant packets arrive for processing. Thus, a rogue DHCPv6 server on a network, or in an ISP, could emit specially crafted router advertisement messages that wake up these clients, exploit the bug, and possibly hijack or crash vulnerable Systemd-powered Linux machines.

Here's the Red Hat Linux summary:

systemd-networkd is vulnerable to an out-of-bounds heap write in the DHCPv6 client when handling options sent by network adjacent DHCP servers. A attacker could exploit this via malicious DHCP server to corrupt heap memory on client machines, resulting in a denial of service or potential code execution.

Felix Wilhelm, of the Google Security team, was credited with discovering the flaw, designated CVE-2018-15688. Wilhelm found that a specially crafted DHCPv6 network packet could trigger "a very powerful and largely controlled out-of-bounds heap write," which could be used by a remote hacker to inject and execute code.

"The overflow can be triggered relatively easy by advertising a DHCPv6 server with a server-id >= 493 characters long," Wilhelm noted.

In addition to Ubuntu and Red Hat Enterprise Linux, Systemd has been adopted as a service manager for Debian, Fedora, CoreOS, Mint, and SUSE Linux Enterprise Server. We're told RHEL 7, at least, does not use the vulnerable component by default.

Systemd creator Lennart Poettering has already published a security fix for the vulnerable component – this should be weaving its way into distros as we type.

If you run a Systemd-based Linux system, and rely on systemd-networkd, update your operating system as soon as you can to pick up the fix when available and as necessary.

The bug will come as another argument against Systemd as the Linux management tool continues to fight for the hearts and minds of admins and developers alike. Though a number of major admins have in recent years adopted and championed it as the replacement for the old Init era, others within the Linux world seem to still be less than impressed with Systemd and Poettering's occasionally controversial management of the tool. ®

Send us news
128 Comments

MX Linux 23.6 brings Debian freshness, without the systemd funk

Bookworm 12.10-based release is a few steps ahead of upstream

Ubuntu 25.04 beta takes flight – but this Plucky Puffin is still molting

'Pudgy' might be more apt given the download size

The most important experimental distro you've never heard of gets new project lead

Plus a fresh version ... nine years after its last

April's Patch Tuesday leaves unlucky Windows Hello users unable to login

Can't Redmond ask its whizz-bang Copilot AI to fix it?

Boeing 787 radio software safety fix didn't work, says Qatar

'Loss of safe separation between aircraft, collision, or runway incursion' is not what we want to hear

Windows Server Update Services live to patch another day

Disconnected device scenarios cause headaches for Microsoft

Zorin OS 17.3 takes the Brave step of changing its default browser from Firefox

To be fair, it sounds like the team has ironed out the more controversial features

Apple belatedly patches actively exploited bugs in older OSes

Cupertino already squashed 'em in more recent releases - which this week get a fresh round of fixes

Both Haiku and Linux get new FOSS Nvidia drivers

Thanks to Collabora's work on Zink and NVK… and indirectly to GPU-maker's FOSS release, too

Fedora 42 beta has so many spins, it'll make your head whirl

The answer to the ultimate question of Linux, the Universe, and Everything?

Credible nerd says stop using atop, doesn't say why, everyone panics

Bad news about the Linux system monitor may be on the way

Panic averted: It was just a bug in Atop after all

Warning of possible problems sparks controversy: Was it OverDAtop?