Back to Database
Status published
Medium
CVE-2018-16866
An out of bounds read was discovered in systemd-journald in...
Vulnerability Description
An out of bounds read was discovered in systemd-journald in the way it parses log messages that terminate with a colon ':'. A local attacker can use this flaw to disclose process memory data. Versions from v221 to v239 are vulnerable.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-16866
Credits & Attribution
No credits recorded in the NVD database.
References
- https://www.debian.org/security/2019/dsa-4367
- https://security.netapp.com/advisory/ntap-20190117-0001/
- https://www.qualys.com/2019/01/09/system-down/system-down.txt
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16866
- https://usn.ubuntu.com/3855-1/
- http://www.securityfocus.com/bid/106527
- https://security.gentoo.org/glsa/201903-07
- http://www.openwall.com/lists/oss-security/2019/05/10/4
- https://seclists.org/bugtraq/2019/May/25
- http://packetstormsecurity.com/files/152841/System-Down-A-systemd-journald-Exploit.html
- http://seclists.org/fulldisclosure/2019/May/21
- https://access.redhat.com/errata/RHSA-2019:2091
- https://access.redhat.com/errata/RHSA-2019:3222
- https://access.redhat.com/errata/RHSA-2020:0593
More from The systemd Project
View All →CVE-2019-3842
In systemd before v242-rc4, it was discovered that pam_systemd does...
Medium
4.5
CVE-2019-3815
A memory leak was discovered in the backport of fixes...
Low
3.3
CVE-2018-16888
It was discovered systemd does not correctly check the content...
Medium
4.4
CVE-2018-16865
An allocation of memory without limits, that could result in...
High
7.5
CVE-2018-16864
An allocation of memory without limits, that could result in...
High
7.4
Affected Vendor
The systemd Project
View all reports →Affected Software
systemd
Vulnerable Versions:
from v221 to v239
Timeline
Official Publish:
January 11th, 2019
Last Modified:
June 9th, 2025
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N