Vulnerability record · CVE-2018-1049 · published 16 February 2018
CVE-2018-1049: Systemd project systemd race condition vulnerability
Systemd Project · Systemd
In systemd prior to 234 a race condition exists between .mount and .automount units such that automount requests from kernel may not be serviced by systemd resulting in kernel holding the mountpoint and any processes that try to use said mount will hang. A race condition like this may lead to denial of service, until mount points are unmounted.
Description
In systemd prior to 234 a race condition exists between .mount and .automount units such that automount requests from kernel may not be serviced by systemd resulting in kernel holding the mountpoint and any processes that try to use said mount will hang. A race condition like this may lead to denial of service, until mount points are unmounted.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected products
11 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securitytracker.com/id/1041520 | Third Party AdvisoryVDB Entry |
| https://access.redhat.com/errata/RHSA-2018:0260 | Third Party Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=1534701 | Issue TrackingPatchThird Party Advisory |
| https://lists.debian.org/debian-lts-announce/2018/11/msg00017.html | Mailing ListThird Party Advisory |
| https://usn.ubuntu.com/3558-1/ | Third Party Advisory |
| http://www.securitytracker.com/id/1041520 | Third Party AdvisoryVDB Entry |
| https://access.redhat.com/errata/RHSA-2018:0260 | Third Party Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=1534701 | Issue TrackingPatchThird Party Advisory |
| https://lists.debian.org/debian-lts-announce/2018/11/msg00017.html | Mailing ListThird Party Advisory |
| https://usn.ubuntu.com/3558-1/ | Third Party Advisory |
Track CVE-2018-1049 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-1049), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.