Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-40226

Опубликовано: 10 апр. 2026
Источник: debian

Описание

In nspawn in systemd 233 through 259 before 260, an escape-to-host action can occur via a crafted optional config file.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
systemdfixed260~rc3-1package
systemdfixed257.13-1~deb13u1trixiepackage
systemdfixed252.39-1~deb12u2bookwormpackage

Примечания

  • https://github.com/systemd/systemd/security/advisories/GHSA-9mj4-rrc3-gjcx

  • Fixed by: https://github.com/systemd/systemd/commit/61bceb1bff4b1f9c126b18dc971ca3e6d8c71c40 (v260-rc3)

  • Fixed by: https://github.com/systemd/systemd/commit/7b85f5498a958e5bb660c703b8f4a71cceed3373 (v260-rc3)

  • Fixed by: https://github.com/systemd/systemd/commit/773fd3b6e72e6c83cbb1cfc1cb20f3793db8649a (v257.12)

  • Fixed by: https://github.com/systemd/systemd/commit/bfa0a842822c4f79da9d47f8a773fd128d8f8a0a (v257.12)

Связанные уязвимости

CVSS3: 6.4
ubuntu
4 месяца назад

In nspawn in systemd 233 through 259 before 260, an escape-to-host action can occur via a crafted optional config file.

CVSS3: 6.4
redhat
4 месяца назад

In nspawn in systemd 233 through 259 before 260, an escape-to-host action can occur via a crafted optional config file.

CVSS3: 6.4
nvd
4 месяца назад

In nspawn in systemd 233 through 259 before 260, an escape-to-host action can occur via a crafted optional config file.

msrc
4 месяца назад

Описание отсутствует

suse-cvrf
13 дней назад

Security update for systemd