In systemd 259 before 260, there is local privilege escalation in systemd-machined because varlink can be used to reach the root namespace.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 10 Apr 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In systemd 259 before 260, there is local privilege escalation in systemd-machined because varlink can be used to reach the root namespace. | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-04-10T18:13:05.818Z
Reserved: 2026-04-10T15:14:21.394Z
Link: CVE-2026-40224
No data.
Status : Received
Published: 2026-04-10T16:16:33.113
Modified: 2026-04-10T16:16:33.113
Link: CVE-2026-40224
No data.
OpenCVE Enrichment
No data.
Weaknesses