systemd, a system and service manager, (as PID 1) hits an assert and freezes execution when an unprivileged IPC API call is made with spurious data. On version v249 and older the effect is not an assert, but stack overwriting, with the attacker controlled content. From version v250 and newer this is not possible as the safety check causes an assert instead. This IPC call was added in v239, so versions older than that are not affected. Versions 260-rc1, 259.2, 258.5, and 257.11 contain patches. No known workarounds are available.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade systemd-udevUpgrade systemd-rpm-macrosUpgrade systemd-journal-remoteUpgrade systemd-develUpgrade systemd-boot-unsignedUpgrade systemd-containerUpgrade systemd-libsUpgrade rhel-net-naming-sysattrsUpgrade systemdUpgrade systemd-pamUpgrade systemd-ukifyUpgrade systemd-oomdUpgrade systemd-resolved | May 6, 2026 | May 5, 2026 |
| Debian | — | Upgrade systemd | Apr 16, 2026 | Apr 16, 2026 |
| Oracle_linux | — | Upgrade rhel-net-naming-sysattrsUpgrade systemd-pamUpgrade systemd-boot-unsignedUpgrade systemd-rpm-macrosUpgrade systemd-containerUpgrade systemd-libsUpgrade systemd-udevUpgrade systemd-ukifyUpgrade systemd-journal-remoteUpgrade systemdUpgrade systemd-develUpgrade systemd-oomdUpgrade systemd-resolved | May 6, 2026 | Mar 23, 2026 |
| Redhat Openshift | — | Upgrade rhcos | Aug 27, 2026 | Mar 23, 2026 |
| Redhat_linux | — | Upgrade systemd-containerUpgrade systemd-develUpgrade systemd-pam-debuginfoUpgrade systemd-journal-remote-debuginfoUpgrade systemd-standalone-sysusers-debuginfoUpgrade systemd-journal-remoteUpgrade systemd-libs-debuginfoUpgrade systemd-pamUpgrade systemd-container-debuginfoUpgrade systemd-udev-debuginfoUpgrade systemd-debugsourceNo solution existsUpgrade systemd-oomdUpgrade systemd-tests-debuginfoUpgrade systemd-resolvedUpgrade systemd-libsUpgrade systemd-debuginfoUpgrade systemd-resolved-debuginfoUpgrade systemd-boot-unsignedUpgrade systemd-boot-unsigned-debuginfoUpgrade systemdUpgrade systemd-rpm-macrosUpgrade systemd-udevUpgrade rhel-net-naming-sysattrsUpgrade systemd-ukifyUpgrade systemd-standalone-tmpfiles-debuginfoUpgrade systemd-oomd-debuginfo | May 7, 2026 | Mar 23, 2026 |
| Rocky_linux | — | Upgrade systemd-develUpgrade systemd-oomd-debuginfoUpgrade systemd-journal-remoteUpgrade systemd-debuginfoUpgrade systemd-container-debuginfoUpgrade systemd-boot-unsigned-debuginfoUpgrade systemdUpgrade systemd-resolved-debuginfoUpgrade systemd-containerUpgrade systemd-libsUpgrade systemd-boot-unsignedUpgrade systemd-libs-debuginfoUpgrade systemd-udev-debuginfoUpgrade systemd-pam-debuginfoUpgrade systemd-resolvedUpgrade systemd-pamUpgrade systemd-debugsourceUpgrade systemd-udevUpgrade systemd-oomdUpgrade systemd-journal-remote-debuginfo | May 25, 2026 | May 21, 2026 |
| Ubuntu | — | Upgrade libudev1Upgrade udevUpgrade libsystemd0Upgrade systemd (Ubuntu Pro)Upgrade udev (Ubuntu Pro)Upgrade systemdUpgrade libudev1 (Ubuntu Pro)Upgrade libsystemd0 (Ubuntu Pro) | Mar 27, 2026 | Mar 23, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | May 27, 2026 | Mar 23, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub