CVE-2018-16866

medium
Published — · Modified —
CVSS v3
CVSS v2
VIR risk
5.5

Description

An out of bounds read was discovered in systemd-journald in the way it parses log messages that terminate with a colon ':'. A local attacker can use this flaw to disclose process memory data. Versions from v221 to v239 are vulnerable.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2018-16866

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2018-16866.html

vendor Authored 2026-05-27

Vendor advisory: arch — https://security.archlinux.org/ASA-201901-4

OS impact

OSVersionStatusFixed in
arch archfixed240.0-3
suse slesaffected
debian debianbookwormfixed240-1
debian debianbullseyefixed240-1
debian debianforkyfixed240-1
debian debiansidfixed240-1
debian debiantrixiefixed240-1

References

Verify integrity in audit chain (admin only). AS-IS.