CVE-2019-15718

medium
Published — · Modified —
CVSS v3
CVSS v2
VIR risk
5.5

Description

In systemd 240, bus_open_system_watch_bind_with_description in shared/bus-util.c (as used by systemd-resolved to connect to the system D-Bus instance), calls sd_bus_set_trusted, which disables access controls for incoming D-Bus messages. An unprivileged user can exploit this by executing D-Bus methods that should be restricted to privileged users, in order to change the system's DNS resolver settings.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2019-15718

vendor Authored 2026-05-27

Vendor advisory: arch — https://security.archlinux.org/ASA-201910-3

OS impact

OSVersionStatusFixed in
arch archfixed243.0-1
debian debianbookwormfixed242-7
debian debianbullseyefixed242-7
debian debianforkyfixed242-7
debian debiansidfixed242-7
debian debiantrixiefixed242-7

References

Verify integrity in audit chain (admin only). AS-IS.