systemd is a suite of basic building blocks for a Linux system. It provides a system and service manager that runs as PID 1 and starts the rest of the system.
systemd provides aggressive parallelization capabilities, uses socket and D-Bus activation for starting services, offers on-demand starting of daemons, keeps track of processes using Linux control groups, maintains mount and automount points, and implements an elaborate transactional dependency-based service control logic. systemd works as a replacement for SysV init.
Other parts include a logging daemon, utilities to control basic system configuration like the hostname, date, locale, maintain a list of logged-in users, running containers and virtual machines, system accounts, runtime directories and settings, and daemons to manage simple network configuration, network time synchronization, log forwarding, and name resolution.
This bug bounty program is paid for by the Sovereign Tech Resilience program.
You can find our repositories on Github
Every valid report that helps us improve the security of the project is welcome, however, in order to qualify for monetary rewards the following eligibility requirements must be met at a minimum:
CVSS is used to rate and categorize vulnerabilities. Vulnerabilities will be publicly disclosed after sufficient time has passed and fixes have been backported where needed, if deemed necessary in coordination with mainstream Linux distributions.
Advisories will be published on the advisory page of our GitHub repository, and where deemed necessary as CVEs and on external mailing-lists like oss-security.
We handle the full disclosure process and expect submitters not to disclose any findings themselves. If requested, we will fully credit the reporters in the advisories.
The process for external reporting is described on GitHub
Scope Type | Scope Name |
---|---|
undefined | systemd (the manager itself) |
undefined | systemd-boot |
undefined | systemd-stub |
undefined | systemd-udev |
undefined | systemd-journald |
undefined | systemd-logind |
undefined | systemd-networkd |
undefined | libsystemd |
undefined | systemd-timesyncd |
undefined | systemd-hostnamed |
undefined | systemd-resolved |
undefined | systemd-cryptenroll |
undefined | systemd-cryptsetup |
undefined | systemd-veritysetup |
undefined | systemd-fstab-generator |
undefined | systemd-gpt-auto-generator |
undefined | systemd-ask-password |
Scope Type | Scope Name |
---|---|
undefined | journal sealing in systemd-journald: there are known issue that need to be solved first, before this feature can be included in the program |
web_application | Anything related to https://systemd.io |
This program crawled on the 2024-04-10 is sorted as bounty.
FireBounty © 2015-2025