systemd-homed contains a local privilege escalation bug via arbitrary system group addition to a local, logged in, homed-managed user
CVSS Details
- CVSS 3.1 Base Score: 6.7
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux_2023 | — | Upgrade systemd-journal-remoteUpgrade systemd-oomd-defaultsUpgrade systemd-journal-remote-debuginfoUpgrade systemd-standalone-sysusers-debuginfoUpgrade systemd-resolved-debuginfoUpgrade systemd-develUpgrade systemd-pam-debuginfoUpgrade systemd-tests-debuginfoUpgrade systemd-standalone-tmpfiles-debuginfoUpgrade systemd-containerUpgrade systemd-networkd-debuginfoUpgrade systemd-debugsourceUpgrade systemd-libs-debuginfoUpgrade systemd-pamUpgrade systemd-standalone-tmpfilesUpgrade systemd-udev-debuginfoUpgrade systemd-networkdUpgrade systemdUpgrade systemd-boot-unsigned-debuginfoUpgrade systemd-resolvedUpgrade systemd-container-debuginfoUpgrade systemd-udevUpgrade systemd-testsUpgrade systemd-standalone-sysusersUpgrade systemd-libsUpgrade systemd-rpm-macrosUpgrade systemd-debuginfoUpgrade systemd-boot-unsigned | Sep 30, 2026 | Aug 10, 2026 |
| Redhat_linux | — | — | Sep 3, 2026 | Aug 10, 2026 |
| Ubuntu | — | Upgrade systemdUpgrade systemd-homedUpgrade systemd-oomd | Aug 11, 2026 | Aug 10, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub