basic/unit-name.c in systemd prior to 246.15, 247.8, 248.5, and 249.1 has a Memory Allocation with an Excessive Size Value (involving strdupa and alloca for a pathname controlled by a local attacker) that results in an operating system crash.
{ "vanir_signatures": [ { "id": "CVE-2021-33910-1c3f15f3", "deprecated": false, "signature_type": "Line", "signature_version": "v1", "target": { "file": "src/basic/unit-name.c" }, "source": "https://github.com/systemd/systemd-stable/commit/764b74113e36ac5219a4b82a05f311b5a92136ce", "digest": { "line_hashes": [ "295455408269373134352364312047732468871", "43586261161881030143337695540596514679", "193731805681192560656540138140781207439", "234345089565047727780801491425519835287", "324375921830458711877362487278178510930", "143913382226387268656648571449825118976", "249353666783312831483115544398788369827", "75084033152122151109689042536574316692", "5644314769794058700180533724555806106", "65128882235487803307668213270905731123", "183803556583342230414319689882972533709", "300206888555267011948129887929833603859", "234953466923105676125704202346521834640" ], "threshold": 0.9 } }, { "id": "CVE-2021-33910-1e3e1f7c", "deprecated": false, "signature_type": "Function", "signature_version": "v1", "target": { "function": "unit_name_path_escape", "file": "src/basic/unit-name.c" }, "source": "https://github.com/systemd/systemd-stable/commit/4a1c5f34bd3e1daed4490e9d97918e504d19733b", "digest": { "function_hash": "238363963586981283236621004435380510899", "length": 450.0 } }, { "id": "CVE-2021-33910-21c0842c", "deprecated": false, "signature_type": "Line", "signature_version": "v1", "target": { "file": "src/basic/unit-name.c" }, "source": "https://github.com/systemd/systemd-stable/commit/4a1c5f34bd3e1daed4490e9d97918e504d19733b", "digest": { "line_hashes": [ "295455408269373134352364312047732468871", "43586261161881030143337695540596514679", "193731805681192560656540138140781207439", "234345089565047727780801491425519835287", "324375921830458711877362487278178510930", "143913382226387268656648571449825118976", "301897454620019740996020042001306739526", "75084033152122151109689042536574316692", "5644314769794058700180533724555806106", "65128882235487803307668213270905731123", "183803556583342230414319689882972533709", "300206888555267011948129887929833603859", "234953466923105676125704202346521834640" ], "threshold": 0.9 } }, { "id": "CVE-2021-33910-4a17b63f", "deprecated": false, "signature_type": "Function", "signature_version": "v1", "target": { "function": "unit_name_path_escape", "file": "src/basic/unit-name.c" }, "source": "https://github.com/systemd/systemd-stable/commit/b00674347337b7531c92fdb65590ab253bb57538", "digest": { "function_hash": "238363963586981283236621004435380510899", "length": 450.0 } }, { "id": "CVE-2021-33910-971cdb97", "deprecated": false, "signature_type": "Line", "signature_version": "v1", "target": { "file": "src/basic/unit-name.c" }, "source": "https://github.com/systemd/systemd-stable/commit/b00674347337b7531c92fdb65590ab253bb57538", "digest": { "line_hashes": [ "295455408269373134352364312047732468871", "43586261161881030143337695540596514679", "193731805681192560656540138140781207439", "234345089565047727780801491425519835287", "324375921830458711877362487278178510930", "143913382226387268656648571449825118976", "301897454620019740996020042001306739526", "75084033152122151109689042536574316692", "5644314769794058700180533724555806106", "65128882235487803307668213270905731123", "183803556583342230414319689882972533709", "300206888555267011948129887929833603859", "234953466923105676125704202346521834640" ], "threshold": 0.9 } }, { "id": "CVE-2021-33910-a5efb150", "deprecated": false, "signature_type": "Line", "signature_version": "v1", "target": { "file": "src/basic/unit-name.c" }, "source": "https://github.com/systemd/systemd-stable/commit/cfd14c65374027b34dbbc4f0551456c5dc2d1f61", "digest": { "line_hashes": [ "295455408269373134352364312047732468871", "43586261161881030143337695540596514679", "193731805681192560656540138140781207439", "234345089565047727780801491425519835287", "324375921830458711877362487278178510930", "143913382226387268656648571449825118976", "301897454620019740996020042001306739526", "75084033152122151109689042536574316692", "5644314769794058700180533724555806106", "65128882235487803307668213270905731123", "183803556583342230414319689882972533709", "300206888555267011948129887929833603859", "234953466923105676125704202346521834640" ], "threshold": 0.9 } }, { "id": "CVE-2021-33910-fe84b142", "deprecated": false, "signature_type": "Function", "signature_version": "v1", "target": { "function": "unit_name_path_escape", "file": "src/basic/unit-name.c" }, "source": "https://github.com/systemd/systemd-stable/commit/764b74113e36ac5219a4b82a05f311b5a92136ce", "digest": { "function_hash": "13991766979645080629156966034899221242", "length": 442.0 } }, { "id": "CVE-2021-33910-ff8fa881", "deprecated": false, "signature_type": "Function", "signature_version": "v1", "target": { "function": "unit_name_path_escape", "file": "src/basic/unit-name.c" }, "source": "https://github.com/systemd/systemd-stable/commit/cfd14c65374027b34dbbc4f0551456c5dc2d1f61", "digest": { "function_hash": "238363963586981283236621004435380510899", "length": 450.0 } } ] }