CVE-2020-13776

medium
Published — · Modified —
CVSS v3
CVSS v2
VIR risk
5.5

Description

systemd through v245 mishandles numerical usernames such as ones composed of decimal digits or 0x followed by hex digits, as demonstrated by use of root privileges when privileges of the 0x0 user account were intended. NOTE: this issue exists because of an incomplete fix for CVE-2017-1000082.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2020-13776

vendor Authored 2026-05-27

Vendor advisory: rocky — https://errata.rockylinux.org/RLSA-2021:1611

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2020-13776.html

OS impact

OSVersionStatusFixed in
suse slesaffected
rockylinux rocky8fixed
debian debianbookwormfixed246-2
debian debianbullseyefixed246-2
debian debianforkyfixed246-2
debian debiansidfixed246-2
debian debiantrixiefixed246-2

References

Verify integrity in audit chain (admin only). AS-IS.