In udev in systemd before 260, local root execution can occur via malicious hardware devices and unsanitized kernel output.
The product does not properly transfer a resource/behavior to another sphere, or improperly imports a resource/behavior from another sphere, in a manner that provides unintended control over that resource.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Systemd | Systemd_project | * | 257.13 (excluding) |
| Systemd | Systemd_project | 258 (including) | 258.7 (excluding) |
| Systemd | Systemd_project | 259 (including) | 259.5 (excluding) |
| Red Hat Hardened Images | RedHat | systemd-main-260.1-2.1.hum1 | * |
| Systemd | Ubuntu | esm-infra/focal | * |
| Systemd | Ubuntu | esm-infra/xenial | * |
| Systemd | Ubuntu | jammy | * |
| Systemd | Ubuntu | noble | * |
| Systemd | Ubuntu | questing | * |
| Systemd | Ubuntu | upstream | * |