systemd Vulnerabilities and Affected Products
Explore source-attributed vulnerabilities associated with systemd products.
Products
- systemd11 vulnerabilities
- systemd-homed1 vulnerability
- systemd-machined1 vulnerability
- systemd-oomd1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-15060MEDIUM | systemd-machined: unprivileged users can terminate arbitrary processesWhen systemd-machined >= v259 (or v258 with a custom `polkit` policy that allows `register-machine` access) is running on a desktop system, an unprivileged user logged in a desktop graphical session can kill arbitrary processes, even privileged ones. - versions older than v259 are not affected, unless unprivileged access is granted for the `register-machine` polkit action via a local, custom policy config file - versions older than v258 are not affected - unrelated to the systemd service manage… | CVSS4.7v3.1 | EPSS0.079% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-16742MEDIUM | systemd-homed: local privilege escalation via missing home-record signature verification on the authenticate pathsystemd-homed contains a local privilege escalation bug via arbitrary system group addition to a local, logged in, homed-managed user | CVSS6.7v3.1 | EPSS0.057% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-15059MEDIUM | systemd-oomd: unprivileged users can terminate arbitrary processesLocal unprivileged users can terminate arbitrary local processes via a systemd-oomd IPC API due to a missing path traversal validation. | CVSS5.5v3.1 | EPSS0.119% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
Generated title:systemd journald ANSI Escape Sequence Injection via ForwardToWallIn systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a "logger -p emerg" command is executed, if ForwardToWall=yes is set. CWE-669Apr 10, 2026 | CVSS2.9v3.1 | EPSS0.173% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2026-40227MEDIUM | Generated title:systemd IPC API Null Element Assertion Denial of ServiceIn systemd 260 before 261, a local unprivileged user can trigger an assert via an IPC API call with an array or map that has a null element. CWE-1025Apr 10, 2026 | CVSS6.2v3.1 | EPSS0.202% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-40226MEDIUM | Generated title:systemd nspawn Escape-to-Host via Crafted Config FileIn nspawn in systemd 233 through 259 before 260, an escape-to-host action can occur via a crafted optional config file. CWE-348Apr 10, 2026 | CVSS6.4v3.1 | EPSS0.072% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-40225MEDIUM | Generated title:systemd udev Local Root Execution via Unsanitized Kernel OutputIn udev in systemd before 260, local root execution can occur via malicious hardware devices and unsanitized kernel output. CWE-669Apr 10, 2026 | CVSS6.4v3.1 | EPSS0.144% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-40224MEDIUM | Generated title:systemd systemd-machined Local Privilege Escalation via VarlinkIn systemd 259 before 260, there is local privilege escalation in systemd-machined because varlink can be used to reach the root namespace. CWE-863Apr 10, 2026 | CVSS6.7v3.1 | EPSS0.079% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-40223MEDIUM | Generated title:systemd Assertion Failure via Delegate=yes Unit with Unset UserIn systemd 258 before 260, a local unprivileged user can trigger an assert when a Delegate=yes and User=<unset> unit exists and is running. CWE-696Apr 10, 2026 | CVSS4.7v3.1 | EPSS0.086% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-29111MEDIUM | systemd: Local unprivileged user can trigger an assertsystemd, a system and service manager, (as PID 1) hits an assert and freezes execution when an unprivileged IPC API call is made with spurious data. On version v249 and older the effect is not an assert, but stack overwriting, with the attacker controlled content. From version v250 and newer this is not possible as the safety check causes an assert instead. This IPC call was added in v239, so versions older than that are not affected. Versions 260-rc1, 259.2, 258.5, and 257.11 contain patches. N… CWE-269Mar 23, 2026 | CVSS5.5v3.1 | EPSS0.121% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2012-1101MEDIUM | systemd 37-1 does not properly handle non-existent services, which causes a denial of service (failure of login procedure). Mar 11, 2020 | CVSS5.5v3.1 | EPSS0.395% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2018-15686HIGH | systemd: reexec state injection: fgets() on overlong lines leads to line splittingA vulnerability in unit_deserialize of systemd allows an attacker to supply arbitrary state across systemd re-execution via NotifyAccess. This can be used to improperly influence systemd execution and possibly lead to root privilege escalation. Affected releases are systemd versions up to and including 239. CWE-502Oct 26, 2018 | CVSS7.8v3.1 | EPSS2.26% | PoCs2 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2018-15688HIGH | Out-of-Bounds write in systemd-networkd dhcpv6 option handlingA buffer overflow vulnerability in the dhcp6 client of systemd allows a malicious dhcp6 server to overwrite heap memory in systemd-networkd. Affected releases are systemd: versions up to and including 239. CWE-120Oct 26, 2018 | CVSS8.8v3.1 | EPSS1.67% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2018-15687HIGH | systemd: chown_one() can dereference symlinksA race condition in chown_one() of systemd allows an attacker to cause systemd to set arbitrary permissions on arbitrary files. Affected releases are systemd versions up to and including 239. CWE-362Oct 26, 2018 | CVSS7.0v3.1 | EPSS1.06% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |