Medium severity4.7NVD Advisory· Published Jan 14, 2019· Updated Jun 17, 2026
CVE-2018-16888
CVE-2018-16888
Description
It was discovered systemd does not correctly check the content of PIDFile files before using it to kill processes. When a service is run from an unprivileged user (e.g. User field set in the service file), a local attacker who is able to write to the PIDFile of the mentioned service may use this flaw to trick systemd into killing other services and/or privileged processes. Versions before v237 are vulnerable.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
15<v237+ 1 more
- (no CPE)range: <v237
- cpe:2.3:a:systemd_project:systemd:*:*:*:*:*:*:*:*range: <237
- The systemd Project/systemdv5Range: v237
- osv-coords6 versionspkg:apk/chainguard/py3.11-systemdpkg:apk/chainguard/py3-supported-systemdpkg:apk/chainguard/py3-systemdpkg:apk/chainguard/py3.10-systemdpkg:apk/chainguard/py3.12-systemdpkg:apk/chainguard/py3.13-systemd
< 0+ 5 more
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*+ 2 more
- cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:19.10:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
- cpe:2.3:a:netapp:active_iq_performance_analytics_services:-:*:*:*:*:*:*:*
- cpe:2.3:a:netapp:element_software:-:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
5- bugzilla.redhat.com/show_bug.cginvdIssue TrackingPatchThird Party Advisory
- access.redhat.com/errata/RHSA-2019:2091nvdThird Party Advisory
- security.netapp.com/advisory/ntap-20190307-0007/nvdThird Party Advisory
- usn.ubuntu.com/4269-1/nvdThird Party Advisory
- lists.apache.org/thread.html/5960a34a524848cd722fd7ab7e2227eac10107b0f90d9d1e9c3caa74%40%3Cuser.cassandra.apache.org%3Envd
News mentions
0No linked articles in our index yet.