CVE Vulnerabilities

CVE-2026-29111

Improper Privilege Management

Published: Mar 23, 2026 | Modified: Apr 15, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
7.8 MODERATE
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

systemd, a system and service manager, (as PID 1) hits an assert and freezes execution when an unprivileged IPC API call is made with spurious data. On version v249 and older the effect is not an assert, but stack overwriting, with the attacker controlled content. From version v250 and newer this is not possible as the safety check causes an assert instead. This IPC call was added in v239, so versions older than that are not affected. Versions 260-rc1, 259.2, 258.5, and 257.11 contain patches. No known workarounds are available.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

NameVendorStart VersionEnd Version
SystemdSystemd_project239 (including)257.11 (excluding)
SystemdSystemd_project258 (including)258.5 (excluding)
SystemdSystemd_project259 (including)259.2 (excluding)
Red Hat Enterprise Linux 10RedHatsystemd-0:257-13.el10_1.3*
Red Hat Enterprise Linux 10RedHatsystemd-0:257-23.el10_2.1*
Red Hat Enterprise Linux 10.0 Extended Update SupportRedHatsystemd-0:257-9.el10_0.2*
Red Hat Enterprise Linux 9RedHatsystemd-0:252-55.el9_7.9*
Red Hat Enterprise Linux 9RedHatsystemd-0:252-67.el9_8.2*
Red Hat Enterprise Linux 9RedHatsystemd-0:252-55.el9_7.9*
Red Hat Enterprise Linux 9RedHatsystemd-0:252-67.el9_8.2*
Red Hat Hardened ImagesRedHatsystemd-main-260.1-2.1.hum1*
Red Hat Insights proxy 1.5RedHatinsights-proxy/insights-proxy-container-rhel9:1780420428*
Red Hat OpenShift distributed tracing 3.9.3RedHatrhosdt/opentelemetry-collector-rhel9:1778056267*
Red Hat OpenShift distributed tracing 3.9.3RedHatrhosdt/opentelemetry-rhel9-operator:1778056233*
Red Hat OpenShift distributed tracing 3.9.3RedHatrhosdt/opentelemetry-target-allocator-rhel9:1778056245*
Red Hat Update Infrastructure 5RedHatrhui5/cds-rhel9:1779798159*
Red Hat Update Infrastructure 5RedHatrhui5/haproxy-rhel9:1779798164*
Red Hat Update Infrastructure 5RedHatrhui5/installer-rhel9:1779798165*
Red Hat Update Infrastructure 5RedHatrhui5/rhua-rhel9:1779798222*
SystemdUbuntuesm-infra/focal*
SystemdUbuntujammy*
SystemdUbuntunoble*
SystemdUbuntuquesting*

Potential Mitigations

References