CVE Vulnerabilities

CVE-2026-40225

Incorrect Resource Transfer Between Spheres

Published: Apr 10, 2026 | Modified: Apr 27, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
6.4 MODERATE
CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

In udev in systemd before 260, local root execution can occur via malicious hardware devices and unsanitized kernel output.

Weakness

The product does not properly transfer a resource/behavior to another sphere, or improperly imports a resource/behavior from another sphere, in a manner that provides unintended control over that resource.

Affected Software

NameVendorStart VersionEnd Version
SystemdSystemd_project*257.13 (excluding)
SystemdSystemd_project258 (including)258.7 (excluding)
SystemdSystemd_project259 (including)259.5 (excluding)
Red Hat Hardened ImagesRedHatsystemd-main-260.1-2.1.hum1*
SystemdUbuntuesm-infra/focal*
SystemdUbuntuesm-infra/xenial*
SystemdUbuntujammy*
SystemdUbuntunoble*
SystemdUbuntuquesting*
SystemdUbuntuupstream*

References