Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-40227

Опубликовано: 10 апр. 2026
Источник: debian
EPSS Низкий

Описание

In systemd 260 before 261, a local unprivileged user can trigger an assert via an IPC API call with an array or map that has a null element.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
systemdfixed260.1-1package
systemdnot-affectedtrixiepackage
systemdnot-affectedbookwormpackage
systemdnot-affectedbullseyepackage

Примечания

  • https://github.com/systemd/systemd/security/advisories/GHSA-848h-497j-8vjq

  • Introduced with: https://github.com/systemd/systemd/commit/799392286ec0797c0a2a1260c444360b47ef36fc (v260-rc1)

  • Fixed by: https://github.com/systemd/systemd/commit/924f5a3461512ac8126fe4423329e3ca802b4d20 (main)

  • Fixed by: https://github.com/systemd/systemd/commit/6f3074088a9f89f89d3188f7b3b4f0ddc0cfc73b (v260.1)

EPSS

Процентиль: 4%
0.00018
Низкий

Связанные уязвимости

CVSS3: 6.2
ubuntu
2 дня назад

In systemd 260 before 261, a local unprivileged user can trigger an assert via an IPC API call with an array or map that has a null element.

CVSS3: 6.2
redhat
5 дней назад

A flaw was found in systemd. A local unprivileged user can exploit this vulnerability by making an Inter-Process Communication (IPC) API call with a specially crafted array or map containing a null element. This can trigger an assert, leading to a Denial of Service (DoS) condition, which makes the system unavailable.

CVSS3: 6.2
nvd
5 дней назад

In systemd 260 before 261, a local unprivileged user can trigger an assert via an IPC API call with an array or map that has a null element.

CVSS3: 6.2
github
5 дней назад

In systemd 260 before 261, a local unprivileged user can trigger an assert via an IPC API call with an array or map that has a null element.

EPSS

Процентиль: 4%
0.00018
Низкий