A race condition in chown_one() of systemd allows an attacker to cause systemd to set arbitrary permissions on arbitrary files. Affected releases are systemd versions up to and including 239.
https://www.exploit-db.com/exploits/45715/
https://usn.ubuntu.com/3816-1/
https://security.gentoo.org/glsa/201810-10