CVE-2018-15686

critical
Published — · Modified —
CVSS v3
CVSS v2
VIR risk
9.5

Description

A vulnerability in unit_deserialize of systemd allows an attacker to supply arbitrary state across systemd re-execution via NotifyAccess. This can be used to improperly influence systemd execution and possibly lead to root privilege escalation. Affected releases are systemd versions up to and including 239.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2018-15686

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2018-15686.html

vendor Authored 2026-05-27

Vendor advisory: arch — https://security.archlinux.org/ASA-201811-11

OS impact

OSVersionStatusFixed in
arch archfixed239.300-1
suse slesaffected
debian debianbookwormfixed239-12
debian debianbullseyefixed239-12
debian debianforkyfixed239-12
debian debiansidfixed239-12
debian debiantrixiefixed239-12

References

Verify integrity in audit chain (admin only). AS-IS.