CVE-2026-40225

MEDIUM

systemd <260 - Privilege Escalation

Title source: llm
STIX 2.1

Description

In udev in systemd before 260, local root execution can occur via malicious hardware devices and unsanitized kernel output.

Scores

CVSS v3 6.4
EPSS 0.0004
EPSS Percentile 12.3%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-669
Status published
Products (2)
systemd/systemd < 260
systemd_project/systemd < 257.13
Published Apr 10, 2026
Tracked Since Apr 10, 2026