systemd, a system and service manager, (as PID 1) hits an assert and freezes execution when an unprivileged IPC API call is made with spurious data. On version v249 and older the effect is not an assert, but stack overwriting, with the attacker controlled content. From version v250 and newer this is not possible as the safety check causes an assert instead. This IPC call was added in v239, so versions older than that are not affected. Versions 260-rc1, 259.2, 258.5, and 257.11 contain patches. No known workarounds are available.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade systemd-udevUpgrade systemd-journal-remoteUpgrade systemd-rpm-macrosUpgrade systemd-develUpgrade systemd-boot-unsignedUpgrade systemd-oomdUpgrade rhel-net-naming-sysattrsUpgrade systemd-resolvedUpgrade systemd-ukifyUpgrade systemd-libsUpgrade systemdUpgrade systemd-containerUpgrade systemd-pam | May 6, 2026 | May 5, 2026 |
| Debian | — | Upgrade systemd | Apr 16, 2026 | Apr 16, 2026 |
| Oracle_linux | — | Upgrade systemd-resolvedUpgrade systemdUpgrade systemd-oomdUpgrade systemd-journal-remoteUpgrade systemd-develUpgrade systemd-containerUpgrade rhel-net-naming-sysattrsUpgrade systemd-ukifyUpgrade systemd-pamUpgrade systemd-udevUpgrade systemd-boot-unsignedUpgrade systemd-rpm-macrosUpgrade systemd-libs | May 6, 2026 | Mar 23, 2026 |
| Redhat Openshift | — | Upgrade rhcos | Aug 27, 2026 | Mar 23, 2026 |
| Redhat_linux | — | Upgrade systemd-debuginfoUpgrade systemd-ukifyUpgrade rhel-net-naming-sysattrsUpgrade systemd-standalone-tmpfiles-debuginfoUpgrade systemd-boot-unsignedUpgrade systemd-oomd-debuginfoUpgrade systemd-resolved-debuginfoUpgrade systemd-udevUpgrade systemd-rpm-macrosUpgrade systemdUpgrade systemd-boot-unsigned-debuginfoUpgrade systemd-journal-remoteUpgrade systemd-container-debuginfoUpgrade systemd-standalone-sysusers-debuginfoNo solution existsUpgrade systemd-develUpgrade systemd-debugsourceUpgrade systemd-libs-debuginfoUpgrade systemd-tests-debuginfoUpgrade systemd-libsUpgrade systemd-oomdUpgrade systemd-pamUpgrade systemd-resolvedUpgrade systemd-udev-debuginfoUpgrade systemd-journal-remote-debuginfoUpgrade systemd-pam-debuginfoUpgrade systemd-container | May 7, 2026 | Mar 23, 2026 |
| Rocky_linux | — | Upgrade systemd-debugsourceUpgrade systemd-udev-debuginfoUpgrade systemd-resolvedUpgrade systemd-pamUpgrade systemd-boot-unsignedUpgrade systemd-libs-debuginfoUpgrade systemd-pam-debuginfoUpgrade systemd-libsUpgrade systemd-udevUpgrade systemd-containerUpgrade systemd-journal-remote-debuginfoUpgrade systemd-oomdUpgrade systemd-oomd-debuginfoUpgrade systemd-journal-remoteUpgrade systemd-resolved-debuginfoUpgrade systemd-container-debuginfoUpgrade systemdUpgrade systemd-develUpgrade systemd-boot-unsigned-debuginfoUpgrade systemd-debuginfo | May 25, 2026 | May 21, 2026 |
| Ubuntu | — | Upgrade libsystemd0 (Ubuntu Pro)Upgrade libudev1 (Ubuntu Pro)Upgrade systemdUpgrade udevUpgrade systemd (Ubuntu Pro)Upgrade libsystemd0Upgrade udev (Ubuntu Pro)Upgrade libudev1 | Mar 27, 2026 | Mar 23, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | May 27, 2026 | Mar 23, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub