Skip to main content

Vendor/product archive

systemd_project / systemd CVEs

Beta · best-effort

55 CVEs tagged to systemd_project / systemd4 Critical, 17 High, 30 Medium, 4 Low, 0 Unrated.

CVE-2026-40228

Published Apr 10, 2026

In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a "logger -p emerg" command is executed, if ForwardToWall=yes is set.

CVSS 2.9 · Low
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-40227

Published Apr 10, 2026

In systemd 260 before 261, a local unprivileged user can trigger an assert via an IPC API call with an array or map that has a null element.

CVSS 6.2 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-40226

Published Apr 10, 2026

In nspawn in systemd 233 through 259 before 260, an escape-to-host action can occur via a crafted optional config file.

CVSS 6.4 · Medium
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2026-40225

Published Apr 10, 2026

In udev in systemd before 260, local root execution can occur via malicious hardware devices and unsanitized kernel output.

CVSS 6.4 · Medium
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2026-40224

Published Apr 10, 2026

In systemd 259 before 260, there is local privilege escalation in systemd-machined because varlink can be used to reach the root namespace.

CVSS 6.7 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-40223

Published Apr 10, 2026

In systemd 258 before 260, a local unprivileged user can trigger an assert when a Delegate=yes and User=<unset> unit exists and is running.

CVSS 4.7 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-29111

Published Mar 23, 2026

systemd, a system and service manager, (as PID 1) hits an assert and freezes execution when an unprivileged IPC API call is made with spurious data. On version v249 and older the…

CVSS 5.5 · Medium
evidence mentions
12
Buzz score
35.6
Vendor/product tagsBeta · best-effort

CVE-2023-31439

Published Jun 13, 2023

An issue was discovered in systemd 253. An attacker can modify the contents of past events in a sealed log file and then adjust the file such that checking the integrity shows no…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-31438

Published Jun 13, 2023

An issue was discovered in systemd 253. An attacker can truncate a sealed log file and then resume log sealing such that checking the integrity shows no error, despite modificatio…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-31437

Published Jun 13, 2023

An issue was discovered in systemd 253. An attacker can modify a sealed log file such that, in some views, not all existing and sealed log messages are displayed. NOTE: the vendor…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-4415

Published Jan 11, 2023

A vulnerability was found in systemd. This security flaw can cause a local information leak due to systemd-coredump not respecting the fs.suid_dumpable kernel setting.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-1101

Published Mar 11, 2020

systemd 37-1 does not properly handle non-existent services, which causes a denial of service (failure of login procedure).

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 55 CVEsPage 1 of 3