yocto ▾
›
kirkstone ▾
›
vulnerability
›
CVE-2026-40225
Component Overview
Vulnerability Overview
Name
CVE-2026-40225
Source
NVD (
link
)
Debian (
link
)
Description
In udev in systemd before 260, local root execution can occur via malicious hardware devices and unsanitized kernel output.
CWEs
CWE-669
Published Date
Apr 10, 2026
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://github.com/systemd/systemd/security/advisories/GHSA-vpfq-8p5f-jcqx
Vendor Advisory
Analysis
#
Affected Component
Analysis
systemd
Exploitable
Vulnerability Ratings
#
6.4
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
systemd
buildroot
2025.02.x
256.17
Exploitable
systemd
buildroot
master
258.7
Not Affected
systemd
yocto
master
259.5
Not Affected
systemd
yocto
scarthgap
255.21
Patched
Resolved with patches
#
systemd (yocto:scarthgap)
#
Title
Author
Resolve
1
udev: check for invalid chars in various fields received from
Luca Boccassi <luca.boccassi@gmail.com>
CVE-2026-40225
2
udev: fix review mixup
Luca Boccassi <luca.boccassi@gmail.com>
CVE-2026-40225