github.com
https://github.com/systemd/systemd/security/advisories/GHSA-848h-497j-8vjq CVE-2026-40227
MEDIUM
systemd IPC API Null Element Assertion Denial of Service
Record summary
CVE-2026-40227 has a selected CVSS score of 6.2 (medium).
Description
In systemd 260 before 261, a local unprivileged user can trigger an assert via an IPC API call with an array or map that has a null element.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 14, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
systemdBrowse systemd / systemdDefault status: unaffected | CVE List | 260 to < 261 | affected |
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-40227