Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-40223

Опубликовано: 10 апр. 2026
Источник: debian

Описание

In systemd 258 before 260, a local unprivileged user can trigger an assert when a Delegate=yes and User=<unset> unit exists and is running.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
systemdfixed260~rc1-1package
systemdnot-affectedtrixiepackage
systemdnot-affectedbookwormpackage
systemdnot-affectedbullseyepackage

Примечания

  • https://github.com/systemd/systemd/security/advisories/GHSA-x4h8-rrrg-q78f

  • Introduced with: https://github.com/systemd/systemd/commit/59857b672ca6a3a9253ef9c888172c5e68243160 (v258-rc1)

  • Fixed by: https://github.com/systemd/systemd/commit/05f5156ad1a3b84b54c104ee375b9ce7b746e0cd (v260-rc1)

Связанные уязвимости

CVSS3: 4.7
ubuntu
2 дня назад

In systemd 258 before 260, a local unprivileged user can trigger an assert when a Delegate=yes and User=<unset> unit exists and is running.

CVSS3: 4.7
redhat
5 дней назад

A flaw was found in systemd, a core component of Linux operating systems. A local user, without special privileges, can exploit this vulnerability. By manipulating a specific systemd unit configuration where delegation is enabled and the user is not set, the user can trigger an internal error, leading to a Denial of Service (DoS). This means the affected system may become unresponsive or crash, impacting its availability.

CVSS3: 4.7
nvd
5 дней назад

In systemd 258 before 260, a local unprivileged user can trigger an assert when a Delegate=yes and User=<unset> unit exists and is running.

CVSS3: 4.7
github
5 дней назад

In systemd 258 before 260, a local unprivileged user can trigger an assert when a Delegate=yes and User=<unset> unit exists and is running.