heartbeat.c in heartbeat before 2.0.6 sets insecure permissions in a shmget call for shared memory, which allows local users to cause an unspecified denial of service via unknown vectors, possibly during a short time window on startup.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.008
EPSS Ranking 50.2%