CVE-2026-40226: Medium severity systemd systemd vulnerability
In nspawn in systemd 233 through 259 before 260, an escape-to-host action can occur via a crafted optional config file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/systemdto a version that resolves this vulnerability.Fixed in 247.3-7+deb11u8Fixed in 252.39-1~deb12u2Fixed in 257.13-1~deb13u1Fixed in 260.1-1Fixed in 261~rc3-1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 255-30 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 255-28 - Upgrade
Upgrade
systemdto a version that resolves this vulnerability.Fixed in 260
Event History
Frequently Asked Questions
What is the severity of CVE-2026-40226?
CVE-2026-40226 is considered a high severity vulnerability due to the potential for an escape-to-host action.
How do I fix CVE-2026-40226?
To mitigate CVE-2026-40226, update systemd to version 260 or later.
What versions of systemd are affected by CVE-2026-40226?
CVE-2026-40226 affects systemd versions 233 through 259.
What impact does CVE-2026-40226 have on system security?
CVE-2026-40226 can allow unauthorized access to the host system, compromising its security.
Is CVE-2026-40226 exploitable remotely?
Yes, CVE-2026-40226 can be exploited remotely if proper safeguards are not in place.