CVE Vulnerabilities

CVE-2026-29111

Improper Privilege Management

Published: Mar 23, 2026 | Modified: Jun 17, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
7.8 MODERATE
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

systemd, a system and service manager, (as PID 1) hits an assert and freezes execution when an unprivileged IPC API call is made with spurious data. On version v249 and older the effect is not an assert, but stack overwriting, with the attacker controlled content. From version v250 and newer this is not possible as the safety check causes an assert instead. This IPC call was added in v239, so versions older than that are not affected. Versions 260-rc1, 259.2, 258.5, and 257.11 contain patches. No known workarounds are available.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

NameVendorStart VersionEnd Version
SystemdSystemd_project239 (including)257.11 (excluding)
SystemdSystemd_project258 (including)258.5 (excluding)
SystemdSystemd_project259 (including)259.2 (excluding)
Red Hat Enterprise Linux 10RedHatsystemd-0:257-13.el10_1.3*
Red Hat Enterprise Linux 10RedHatsystemd-0:257-23.el10_2.1*
Red Hat Enterprise Linux 10.0 Extended Update SupportRedHatsystemd-0:257-9.el10_0.2*
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportRedHatsystemd-0:239-45.el8_4.17*
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-OnRedHatsystemd-0:239-45.el8_4.17*
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportRedHatsystemd-0:239-58.el8_6.16*
Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-OnRedHatsystemd-0:239-58.el8_6.16*
Red Hat Enterprise Linux 8.8 Telecommunications Update ServiceRedHatsystemd-0:239-74.el8_8.7*
Red Hat Enterprise Linux 8.8 Update Services for SAP SolutionsRedHatsystemd-0:239-74.el8_8.7*
Red Hat Enterprise Linux 9RedHatsystemd-0:252-55.el9_7.9*
Red Hat Enterprise Linux 9RedHatsystemd-0:252-67.el9_8.2*
Red Hat Enterprise Linux 9RedHatsystemd-0:252-55.el9_7.9*
Red Hat Enterprise Linux 9RedHatsystemd-0:252-67.el9_8.2*
Red Hat Enterprise Linux 9.2 Update Services for SAP SolutionsRedHatsystemd-0:252-14.el9_2.11*
Red Hat Enterprise Linux 9.4 Update Services for SAP SolutionsRedHatsystemd-0:252-32.el9_4.11*
Red Hat Enterprise Linux 9.6 Extended Update SupportRedHatsystemd-0:252-51.el9_6.6*
Red Hat Hardened ImagesRedHatsystemd-main-260.1-2.1.hum1*
Red Hat Insights proxy 1.5RedHatinsights-proxy/insights-proxy-container-rhel9:1780420428*
Red Hat OpenShift distributed tracing 3.9.2RedHatrhosdt/opentelemetry-collector-rhel9:1778056267*
Red Hat OpenShift distributed tracing 3.9.2RedHatrhosdt/opentelemetry-rhel9-operator:1778056233*
Red Hat OpenShift distributed tracing 3.9.2RedHatrhosdt/opentelemetry-target-allocator-rhel9:1778056245*
Red Hat Update Infrastructure 5RedHatrhui5/cds-rhel9:1779798159*
Red Hat Update Infrastructure 5RedHatrhui5/haproxy-rhel9:1779798164*
Red Hat Update Infrastructure 5RedHatrhui5/installer-rhel9:1779798165*
Red Hat Update Infrastructure 5RedHatrhui5/rhua-rhel9:1779798222*
SystemdUbuntuesm-infra/focal*
SystemdUbuntujammy*
SystemdUbuntunoble*
SystemdUbuntuquesting*

Potential Mitigations

References