CVE detail
CVE-2026-29111
systemd, a system and service manager, (as PID 1) hits an assert and freezes execution when an unprivileged IPC API call is made with spurious data. On version v249 and older the effect is not an assert, but stack overwriting, with the attacker controlled content. From version v250 and newer this is not possible as the safety check causes an assert instead. This IPC call was added in v239, so versions older than that are not affected. Versions 260-rc1, 259.2, 258.5, and 257.11 contain patches. No known workarounds are available.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 25.6 · diversity 10.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
12 source links · newest first
- Debian 13.5 point release lands with security fixes, bug patchesHelp Net Security
Debian 13.5 is the fifth point release for the stable distribution “trixie.” The update folds in roughly 100 Debian Security Advisories and corrections for more than 130 source packages, covering everything from the Linux kernel and Apache HTTP Server to OpenSSH, sudo, systemd, OpenSSL, glibc, and FreeRDP. Fresh installer images carrying the same fixes will follow at the regular download locations. Sysadmins running trixie do not need to reinstall. Existing media remain valid, and machines … More →
newswww.helpnetsecurity.comMay 17, 2026, 10:03 PM No excerpt available.
Exploitgithub.comMar 23, 2026, 10:16 PMNo excerpt available.
Exploitgithub.comMar 23, 2026, 10:16 PMNo excerpt available.
Exploitgithub.comMar 23, 2026, 10:16 PMNo excerpt available.
Exploitgithub.comMar 23, 2026, 10:16 PMNo excerpt available.
Exploitgithub.comMar 23, 2026, 10:16 PMNo excerpt available.
Exploitgithub.comMar 23, 2026, 10:16 PMNo excerpt available.
Exploitgithub.comMar 23, 2026, 10:16 PMNo excerpt available.
Exploitgithub.comMar 23, 2026, 10:16 PMNo excerpt available.
Exploitgithub.comMar 23, 2026, 10:16 PMNo excerpt available.
Exploitgithub.comMar 23, 2026, 10:16 PMNo excerpt available.
Exploitgithub.comMar 23, 2026, 10:16 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2023-26604CVSS 7.8 · High
systemd before 247 does not adequately block local privilege escalation for some Sudo configurations, e.g., plausible sudoers files in which the "systemctl status" command may be…
- CVE-2020-13776CVSS 6.7 · Medium
systemd through v245 mishandles numerical usernames such as ones composed of decimal digits or 0x followed by hex digits, as demonstrated by use of root privileges when privileges…
- CVE-2019-3843CVSS 7.8 · High
It was discovered that a systemd service that uses DynamicUser property can create a SUID/SGID binary that would be allowed to run as the transient service UID/GID even after the…
- CVE-2018-16888CVSS 4.7 · Medium
It was discovered systemd does not correctly check the content of PIDFile files before using it to kill processes. When a service is run from an unprivileged user (e.g. User field…
- CVE-2017-1000082CVSS 9.8 · Critical
systemd v233 and earlier fails to safely parse usernames starting with a numeric digit (e.g. "0day"), running the service in question with root privileges rather than the user int…
- CVE-2026-12144CVSS 8.8 · High
The Wholesale for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.5. This is due to the `save_requests_meta()` fun…