Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-40226

Опубликовано: 10 апр. 2026
Источник: redhat
CVSS3: 6.4

Описание

In nspawn in systemd 233 through 259 before 260, an escape-to-host action can occur via a crafted optional config file.

A flaw was found in nspawn, a container runtime environment within systemd. A local attacker or a process within an nspawn container could exploit this vulnerability by using a specially crafted optional configuration file. This could allow the attacker to escape the container's isolation and execute arbitrary actions on the host system.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10NetworkManagerNot affected
Red Hat Enterprise Linux 10rpm-ostreeNot affected
Red Hat Enterprise Linux 10systemdNot affected
Red Hat Enterprise Linux 7systemdNot affected
Red Hat Enterprise Linux 8NetworkManagerNot affected
Red Hat Enterprise Linux 8systemdNot affected
Red Hat Enterprise Linux 9NetworkManagerNot affected
Red Hat Enterprise Linux 9systemdNot affected
Red Hat OpenShift Container Platform 4NetworkManagerNot affected
Red Hat OpenShift Container Platform 4openshift/ose-rhel-coreos-8Not affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-348
https://bugzilla.redhat.com/show_bug.cgi?id=2457326systemd: systemd nspawn: Escape-to-host action via crafted config file

6.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.4
ubuntu
6 месяцев назад

In nspawn in systemd 233 through 259 before 260, an escape-to-host action can occur via a crafted optional config file.

CVSS3: 6.4
nvd
6 месяцев назад

In nspawn in systemd 233 through 259 before 260, an escape-to-host action can occur via a crafted optional config file.

CVSS3: 6.4
msrc
4 месяца назад

In nspawn in systemd 233 through 259 before 260, an escape-to-host action can occur via a crafted optional config file.

CVSS3: 6.4
debian
6 месяцев назад

In nspawn in systemd 233 through 259 before 260, an escape-to-host act ...

suse-cvrf
2 месяца назад

Security update for systemd

6.4 Medium

CVSS3