Logo
vulnerabilityCVE-2026-29111
Name
CVE-2026-29111
Source
NVD ( link)Debian ( link)
Description
systemd, a system and service manager, (as PID 1) hits an assert and freezes execution when an unprivileged IPC API call is made with spurious data. On version v249 and older the effect is not an assert, but stack overwriting, with the attacker controlled content. From version v250 and newer this is not possible as the safety check causes an assert instead. This IPC call was added in v239, so versions older than that are not affected. Versions 260-rc1, 259.2, 258.5, and 257.11 contain patches. No known workarounds are available.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
systemd
Exploitable

Vulnerability Ratings#


5.5
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
256.17
Exploitable
buildroot
master
258.7
Not Affected
yocto
kirkstone
250.14
Exploitable
yocto
master
259.5
Not Affected