The managerdispatchnotify_fd function in systemd allows local users to cause a denial of service (system hang) via a zero-length message received over a notify socket, which causes an error to be returned and the notification handler to be disabled.
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "libsystemd-dev-dbgsym": "229-4ubuntu11", "libsystemd0": "229-4ubuntu11", "udev": "229-4ubuntu11", "systemd-coredump": "229-4ubuntu11", "libudev-dev-dbgsym": "229-4ubuntu11", "systemd-dbg": "229-4ubuntu11", "libnss-resolve": "229-4ubuntu11", "systemd-container-dbgsym": "229-4ubuntu11", "systemd-container": "229-4ubuntu11", "systemd-sysv": "229-4ubuntu11", "libudev-dev": "229-4ubuntu11", "libnss-myhostname": "229-4ubuntu11", "libnss-resolve-dbgsym": "229-4ubuntu11", "udev-udeb-dbgsym": "229-4ubuntu11", "systemd-sysv-dbgsym": "229-4ubuntu11", "systemd-dbgsym": "229-4ubuntu11", "systemd-coredump-dbgsym": "229-4ubuntu11", "libnss-mymachines-dbgsym": "229-4ubuntu11", "systemd-journal-remote-dbgsym": "229-4ubuntu11", "libpam-systemd": "229-4ubuntu11", "libsystemd-dev": "229-4ubuntu11", "libudev1-udeb": "229-4ubuntu11", "libudev1-udeb-dbgsym": "229-4ubuntu11", "systemd-journal-remote": "229-4ubuntu11", "libudev1-dbgsym": "229-4ubuntu11", "libnss-myhostname-dbgsym": "229-4ubuntu11", "udev-dbgsym": "229-4ubuntu11", "udev-udeb": "229-4ubuntu11", "libpam-systemd-dbgsym": "229-4ubuntu11", "libudev1": "229-4ubuntu11", "libnss-mymachines": "229-4ubuntu11", "libsystemd0-dbgsym": "229-4ubuntu11", "systemd": "229-4ubuntu11" } ] }