CVE-2026-15059: systemd-oomd: unprivileged users can terminate arbitrary processes
Published Aug 10, 2026
·Updated
Local unprivileged users can terminate arbitrary local processes via a systemd-oomd IPC API due to a missing path traversal validation.
Affected Software
1 affected component
systemd-oomd
Event History
Aug 10, 2026
CVE Published
via MITRE·01:02 PM
Data Sourced
via MITRE·01:02 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-15059?
The severity of CVE-2026-15059 is medium with a score of 5.5.
2
How does CVE-2026-15059 allow unprivileged users to terminate processes?
CVE-2026-15059 allows unprivileged users to terminate arbitrary local processes via a systemd-oomd IPC API due to insufficient path traversal validation.
3
What is the risk associated with CVE-2026-15059?
CVE-2026-15059 has a risk score of 32, indicating moderate potential for impact.
4
What products are affected by CVE-2026-15059?
The affected product by CVE-2026-15059 is systemd-oomd.
5
How can users mitigate CVE-2026-15059?
To mitigate CVE-2026-15059, users should restrict access to the systemd-oomd IPC API to authorized users only.