A race condition in chown_one() of systemd allows an attacker to cause systemd to set arbitrary permissions on arbitrary files. Affected releases are systemd versions up to and including 239.
https://github.com/systemd/systemd/pull/10517/commits
https://security.gentoo.org/glsa/201810-10