Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-40224

Опубликовано: 10 апр. 2026
Источник: debian

Описание

In systemd 259 before 260, there is local privilege escalation in systemd-machined because varlink can be used to reach the root namespace.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
systemdfixed260~rc2-1package
systemdnot-affectedtrixiepackage
systemdnot-affectedbookwormpackage
systemdnot-affectedbullseyepackage

Примечания

  • https://github.com/systemd/systemd/security/advisories/GHSA-6pwp-j5vg-5j6m

  • Introduced with: https://github.com/systemd/systemd/commit/adaff8eb35d9c471af81fddaa4403bc5843a256f (v258-rc1)

  • Fixed by: https://github.com/systemd/systemd/commit/e5a5656b55725b3674419b67a3f0287f37781860 (v260-rc2)

Связанные уязвимости

CVSS3: 6.7
ubuntu
2 дня назад

In systemd 259 before 260, there is local privilege escalation in systemd-machined because varlink can be used to reach the root namespace.

CVSS3: 6.7
redhat
5 дней назад

A flaw was found in systemd-machined, a component of systemd. A local attacker can exploit a vulnerability related to how varlink interacts with the root namespace. This can lead to local privilege escalation, allowing the attacker to gain elevated access on the system.

CVSS3: 6.7
nvd
5 дней назад

In systemd 259 before 260, there is local privilege escalation in systemd-machined because varlink can be used to reach the root namespace.

CVSS3: 6.7
github
5 дней назад

In systemd 259 before 260, there is local privilege escalation in systemd-machined because varlink can be used to reach the root namespace.