{"id":"CVE-2020-1712","details":"A heap use-after-free vulnerability was found in systemd before version v245-rc1, where asynchronous Polkit queries are performed while handling dbus messages. A local unprivileged attacker can abuse this flaw to crash systemd services or potentially execute code and elevate their privileges, by sending specially crafted dbus messages.","modified":"2026-08-07T16:49:43.902659Z","published":"2020-03-31T17:15:26.577Z","related":["CGA-hmqq-hf7f-vfvx","SUSE-RU-2020:0793-1","SUSE-SU-2020:0331-1","SUSE-SU-2020:0335-1","SUSE-SU-2020:0353-1","openSUSE-SU-2020:0208-1","openSUSE-SU-2024:11420-1"],"database_specific":{"unresolved_ranges":[{"source":"CPE_STRING","vendor_product":"debian:debian_linux","cpes":["cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"9.0"},{"last_affected":"9.0"}]},{"source":"CPE_STRING","vendor_product":"redhat:ceph_storage","cpes":["cpe:2.3:a:redhat:ceph_storage:4.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"4.0"},{"last_affected":"4.0"}]},{"cpes":["cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"8.0"},{"last_affected":"8.0"}],"source":"CPE_STRING","vendor_product":"redhat:enterprise_linux"},{"vendor_product":"redhat:migration_toolkit","cpes":["cpe:2.3:a:redhat:migration_toolkit:1.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"1.0"},{"last_affected":"1.0"}],"source":"CPE_STRING"},{"cpes":["cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"4.0"},{"last_affected":"4.0"}],"source":"CPE_STRING","vendor_product":"redhat:openshift_container_platform"}]},"references":[{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2022/06/msg00025.html"},{"type":"FIX","url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1712"},{"type":"FIX","url":"https://github.com/systemd/systemd/commit/1068447e6954dc6ce52f099ed174c442cb89ed54"},{"type":"FIX","url":"https://github.com/systemd/systemd/commit/637486261528e8aa3da9f26a4487dc254f4b7abb"},{"type":"FIX","url":"https://github.com/systemd/systemd/commit/bc130b6858327b382b07b3985cf48e2aa9016b2d"},{"type":"FIX","url":"https://github.com/systemd/systemd/commit/ea0d0ede03c6f18dbc5036c5e9cccf97e415ccc2"},{"type":"FIX","url":"https://www.openwall.com/lists/oss-security/2020/02/05/1"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/systemd/systemd","events":[{"introduced":"0"},{"last_affected":"db9c5ae73e23d816e2df2a3e10a9a2a60b5b3ed7"},{"fixed":"1068447e6954dc6ce52f099ed174c442cb89ed54"},{"fixed":"637486261528e8aa3da9f26a4487dc254f4b7abb"},{"fixed":"bc130b6858327b382b07b3985cf48e2aa9016b2d"},{"fixed":"ea0d0ede03c6f18dbc5036c5e9cccf97e415ccc2"}],"database_specific":{"cpe":"cpe:2.3:a:systemd_project:systemd:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"244"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["v244","v244-rc1","v243","v243-rc2","v243-rc1","v242","v242-rc4","v242-rc3","v242-rc2","v242-rc1","v241","v241-rc2","v241-rc1","v240","v239","v238","v237","v236","v235","v234","v233","v232","v231","v230","v229","v228","v227","v226","v225","v224","v223","v222","v221","v219","v220","v218","v217","v216","v215","v214","v213","v212","v211","v210","v209","v208","v207","v206","v205","v204","v203","v202","v201","v200","v199","v198","v197","v196","v195","v194","v193","v192","v191","v190","v189","v188","v187","v186","v185","v184","v183","v44","v43","v42","v41","v40","v39","v38","v37","v36","v35","v34","v33","v32","v31","v30","v29","v28","v27","v26","v25","v24","v23","v22","v21","v20","v19","v18","v17","v16","v15","v14","v13","v12","v11","v10","v9","v8","v7","v6","v5","v4","v3","v2","v1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-1712.json","vanir_signatures_modified":"2026-08-07T16:49:43Z","vanir_signatures":[{"source":"https://github.com/systemd/systemd/commit/637486261528e8aa3da9f26a4487dc254f4b7abb","target":{"file":"src/shared/bus-polkit.c","function":"async_polkit_query_free"},"deprecated":false,"digest":{"function_hash":"249541810590335694009610159207201220281","length":339},"id":"CVE-2020-1712-083dfb5f","signature_type":"Function","signature_version":"v1"},{"deprecated":false,"digest":{"function_hash":"74549539480005360539949729723206989023","length":2874},"id":"CVE-2020-1712-7c69b8e3","signature_type":"Function","signature_version":"v1","source":"https://github.com/systemd/systemd/commit/637486261528e8aa3da9f26a4487dc254f4b7abb","target":{"file":"src/shared/bus-polkit.c","function":"bus_verify_polkit_async"}},{"id":"CVE-2020-1712-8dfe3500","signature_type":"Line","signature_version":"v1","source":"https://github.com/systemd/systemd/commit/1068447e6954dc6ce52f099ed174c442cb89ed54","target":{"file":"src/systemd/sd-bus.h"},"deprecated":false,"digest":{"line_hashes":["201651851398158219089139026364454349753","9987944486027707297738265898816304116","192221843579112265559191630782876604232","72822982747573861780012777657069221814"],"threshold":0.9}},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/systemd/systemd/commit/637486261528e8aa3da9f26a4487dc254f4b7abb","target":{"file":"src/shared/bus-polkit.c","function":"async_polkit_callback"},"deprecated":false,"digest":{"function_hash":"191952696935465987918037642341044558598","length":572},"id":"CVE-2020-1712-c78bba3e"},{"deprecated":false,"digest":{"line_hashes":["97053741425443050450208921739222569203","303460527606453710252220666868808145400","18219807215661718443382219123539589712","60261091367737920122821757682504535056","86264706304329535586929432165729739622","337390672199881346205475444548683382521","152562335154503867169907437275077137083","84211952852498673684248562065377075652","324726152797087188705084363045825558251","325970457268498492598214286673190530565","202566744084947735033800918550045650693","194309138071813940665718909269028112190","188997586095725752447519276072764071862","293185299188085331962123844476277735666","320138298323880858161113515815715150458","170379373050637717031754180073892094889","29309665073518276997283992467703573698","165225009145589773428426232127941023680","12321488664809828297015490366106267649","172883744573346081802393080925107117215","75285956263270984207625071252672351081","315481932615129614536008509789990866994","264579120630678275163303016554424061509","234214297483417905214744801498590492828","286908870466118591068503739348901791428","110910070697038590601846380901570703937","147634743858309359957750709512817985592","162589724996563957724767291619418661351","16959055153679824806685267226897867923","76055295512511461434023416680211844859","38713159073670226927111661739781666952","189612858139979274090890865335185172413","154430203011226137819958604224372838126","75389190473008594185108810388326130324","63132286548534368094653651953345052127","294940776886412801592379028783519818267","102301407515608068841865372922431621910","328716495739662205636254361842872047961","196405144638830216506361432807297143715","93356589517045076911522842971448963126","78433439633613489244827728211361246118","205368781931337343468642178564182860212","184223870634894539720575251196499487422","145323608060584930670486582064995568406","43700365621748513773381156876425890970","340123359266940267596657940112607734072","268992061929188121712297464734694520667","30256143953995422663035365047298676842","155909894963427971346953495920941861395","125229967853273817950243613133490540349","244837636105294919696140145482111912276","87390459365384605435053796704959503040","141682537757708057625738963301879324175","25716083193282531004342174123650260090"],"threshold":0.9},"id":"CVE-2020-1712-d35a0e1f","signature_type":"Line","signature_version":"v1","source":"https://github.com/systemd/systemd/commit/637486261528e8aa3da9f26a4487dc254f4b7abb","target":{"file":"src/shared/bus-polkit.c"}}]}},{"ranges":[{"type":"GIT","repo":"https://github.com/systemd/systemd-stable","events":[{"introduced":"0"},{"last_affected":"db9c5ae73e23d816e2df2a3e10a9a2a60b5b3ed7"}],"database_specific":{"cpe":"cpe:2.3:a:systemd_project:systemd:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"244"}],"source":"CPE_RANGE"}}],"versions":["v244","v244-rc1","v243","v243-rc2","v243-rc1","v242","v242-rc4","v242-rc3","v242-rc2","v242-rc1","v241","v241-rc2","v241-rc1","v240","v239","v238","v237","v236","v235","v234","v233","v232","v231","v230","v229","v228","v227","v226","v225","v224","v223","v222","v221","v219","v220","v218","v217","v216","v215","v214","v213","v212","v211","v210","v208","v209","v201","v204","v207","v206","v205","v203","v202","v200","v199","v198","v197","v196","systemd-v196","v195","systemd-v195","v194","systemd-v194","v193","systemd-v193","v192","systemd-v192","v191","systemd-v191","v190","systemd-v190","v189","systemd-v189","v188","systemd-v188","v187","systemd-v187","v186","systemd-v186","v185","systemd-v185","v184","systemd-v184","v183","systemd-v183","v44","systemd-v44","v43","systemd-v43","v42","systemd-v42","v41","systemd-v41","v40","systemd-v40","v39","systemd-v39","v38","systemd-v38","v37","systemd-v37","v36","systemd-v36","v35","systemd-v35","v34","systemd-v34","v33","systemd-v33","v32","systemd-v32","v31","systemd-v31","v30","systemd-v30","v29","systemd-v29","v28","systemd-v28","v27","systemd-v27","v26","systemd-v26","v25","systemd-v25","v24","systemd-v24","v23","systemd-v23","v22","systemd-v22","v21","systemd-v21","v20","systemd-v20","v19","systemd-v19","v18","systemd-v18","v17","systemd-v17","v16","systemd-v16","v15","systemd-v15","v14","systemd-v14","v13","systemd-v13","v12","systemd-v12","v11","systemd-v11","v10","systemd-v10","v9","systemd-v9","v8","systemd-v8","v7","systemd-v7","v6","systemd-v6","v5","systemd-v5","v4","systemd-v4","v3","systemd-v3","v2","systemd-v2","v1","systemd-v1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-1712.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}