PatchSiren

Systemd Project CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Systemd Project CVE published 2017-01-23

CVE-2016-10156

CVE-2016-10156 is a local privilege-escalation flaw in systemd 228 affecting the timers feature. According to NVD, an attacker with local access and limited privileges could trigger creation of world-writable SUID files, which may allow escalation to root. The issue was fixed in systemd 229 and is rated High severity (CVSS 7.8).