rpm package
opensuse/systemd-mini&distro=openSUSE Leap 16.0
pkg:rpm/opensuse/systemd-mini&distro=openSUSE%20Leap%2016.0
Vulnerabilities (4)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-16742 | Med | 6.7 | < 257.13-160000.4.1 | 257.13-160000.4.1 | Aug 10, 2026 | systemd-homed contains a local privilege escalation bug via arbitrary system group addition to a local, logged in, homed-managed user | |
| CVE-2026-40226 | Med | 6.4 | < 257.13-160000.4.1 | 257.13-160000.4.1 | Apr 10, 2026 | In nspawn in systemd 233 through 259 before 260, an escape-to-host action can occur via a crafted optional config file. | |
| CVE-2026-29111 | Med | 5.5 | < 257.13-160000.4.1 | 257.13-160000.4.1 | Mar 23, 2026 | systemd, a system and service manager, (as PID 1) hits an assert and freezes execution when an unprivileged IPC API call is made with spurious data. On version v249 and older the effect is not an assert, but stack overwriting, with the attacker controlled content. From version v2 | |
| CVE-2026-4105 | Med | 6.7 | < 257.13-160000.4.1 | 257.13-160000.4.1 | Mar 13, 2026 | A flaw was found in systemd. The systemd-machined service contains an Improper Access Control vulnerability due to insufficient validation of the class parameter in the RegisterMachine D-Bus (Desktop Bus) method. A local unprivileged user can exploit this by attempting to registe |
- affected < 257.13-160000.4.1fixed 257.13-160000.4.1
systemd-homed contains a local privilege escalation bug via arbitrary system group addition to a local, logged in, homed-managed user
- affected < 257.13-160000.4.1fixed 257.13-160000.4.1
In nspawn in systemd 233 through 259 before 260, an escape-to-host action can occur via a crafted optional config file.
- affected < 257.13-160000.4.1fixed 257.13-160000.4.1
systemd, a system and service manager, (as PID 1) hits an assert and freezes execution when an unprivileged IPC API call is made with spurious data. On version v249 and older the effect is not an assert, but stack overwriting, with the attacker controlled content. From version v2
- affected < 257.13-160000.4.1fixed 257.13-160000.4.1
A flaw was found in systemd. The systemd-machined service contains an Improper Access Control vulnerability due to insufficient validation of the class parameter in the RegisterMachine D-Bus (Desktop Bus) method. A local unprivileged user can exploit this by attempting to registe