CVE Vulnerabilities

CVE-2026-40228

Incorrect Resource Transfer Between Spheres

Published: Apr 10, 2026 | Modified: May 05, 2026
CVSS 3.x
3.3
LOW
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
2.9 LOW
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a logger -p emerg command is executed, if ForwardToWall=yes is set.

Weakness

The product does not properly transfer a resource/behavior to another sphere, or improperly imports a resource/behavior from another sphere, in a manner that provides unintended control over that resource.

Affected Software

NameVendorStart VersionEnd Version
SystemdSystemd_project259 (including)259 (including)
Red Hat Hardened ImagesRedHatsystemd-main-260.1-2.1.hum1*
SystemdUbuntuesm-infra/xenial*

References