Products

Showing 14 vulnerabilities on this page

Signals CISA KEV Ransomware Nuclei
systemd vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

systemd-machined: unprivileged users can terminate arbitrary processes

When systemd-machined >= v259 (or v258 with a custom `polkit` policy that allows `register-machine` access) is running on a desktop system, an unprivileged user logged in a desktop graphical session can kill arbitrary processes, even privileged ones. - versions older than v259 are not affected, unless unprivileged access is granted for the `register-machine` polkit action via a local, custom policy config file - versions older than v258 are not affected - unrelated to the systemd service manage

CWE-284CWE-862Aug 10, 2026
CVSS4.7v3.1EPSS0.079%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

systemd-homed: local privilege escalation via missing home-record signature verification on the authenticate path

systemd-homed contains a local privilege escalation bug via arbitrary system group addition to a local, logged in, homed-managed user

CWE-269CWE-347Aug 10, 2026
CVSS6.7v3.1EPSS0.057%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

systemd-oomd: unprivileged users can terminate arbitrary processes

Local unprivileged users can terminate arbitrary local processes via a systemd-oomd IPC API due to a missing path traversal validation.

CWE-22CWE-59Aug 10, 2026
CVSS5.5v3.1EPSS0.119%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:systemd journald ANSI Escape Sequence Injection via ForwardToWall

In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a "logger -p emerg" command is executed, if ForwardToWall=yes is set.

CWE-669Apr 10, 2026
CVSS2.9v3.1EPSS0.173%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:systemd IPC API Null Element Assertion Denial of Service

In systemd 260 before 261, a local unprivileged user can trigger an assert via an IPC API call with an array or map that has a null element.

CWE-1025Apr 10, 2026
CVSS6.2v3.1EPSS0.202%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:systemd nspawn Escape-to-Host via Crafted Config File

In nspawn in systemd 233 through 259 before 260, an escape-to-host action can occur via a crafted optional config file.

CWE-348Apr 10, 2026
CVSS6.4v3.1EPSS0.072%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:systemd udev Local Root Execution via Unsanitized Kernel Output

In udev in systemd before 260, local root execution can occur via malicious hardware devices and unsanitized kernel output.

CWE-669Apr 10, 2026
CVSS6.4v3.1EPSS0.144%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:systemd systemd-machined Local Privilege Escalation via Varlink

In systemd 259 before 260, there is local privilege escalation in systemd-machined because varlink can be used to reach the root namespace.

CWE-863Apr 10, 2026
CVSS6.7v3.1EPSS0.079%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:systemd Assertion Failure via Delegate=yes Unit with Unset User

In systemd 258 before 260, a local unprivileged user can trigger an assert when a Delegate=yes and User=<unset> unit exists and is running.

CWE-696Apr 10, 2026
CVSS4.7v3.1EPSS0.086%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

systemd: Local unprivileged user can trigger an assert

systemd, a system and service manager, (as PID 1) hits an assert and freezes execution when an unprivileged IPC API call is made with spurious data. On version v249 and older the effect is not an assert, but stack overwriting, with the attacker controlled content. From version v250 and newer this is not possible as the safety check causes an assert instead. This IPC call was added in v239, so versions older than that are not affected. Versions 260-rc1, 259.2, 258.5, and 257.11 contain patches. N

CWE-269Mar 23, 2026
CVSS5.5v3.1EPSS0.121%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

systemd 37-1 does not properly handle non-existent services, which causes a denial of service (failure of login procedure).

Mar 11, 2020
CVSS5.5v3.1EPSS0.395%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

systemd: reexec state injection: fgets() on overlong lines leads to line splitting

A vulnerability in unit_deserialize of systemd allows an attacker to supply arbitrary state across systemd re-execution via NotifyAccess. This can be used to improperly influence systemd execution and possibly lead to root privilege escalation. Affected releases are systemd versions up to and including 239.

CWE-502Oct 26, 2018
CVSS7.8v3.1EPSS2.26%PoCs2SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Out-of-Bounds write in systemd-networkd dhcpv6 option handling

A buffer overflow vulnerability in the dhcp6 client of systemd allows a malicious dhcp6 server to overwrite heap memory in systemd-networkd. Affected releases are systemd: versions up to and including 239.

CWE-120Oct 26, 2018
CVSS8.8v3.1EPSS1.67%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

systemd: chown_one() can dereference symlinks

A race condition in chown_one() of systemd allows an attacker to cause systemd to set arbitrary permissions on arbitrary files. Affected releases are systemd versions up to and including 239.

CWE-362Oct 26, 2018
CVSS7.0v3.1EPSS1.06%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX