REDHAT-BUG-2450505: Medium severity systemd systemd vulnerability

Published Mar 23, 2026
·
Updated

systemd, a system and service manager, (as PID 1) hits an assert and freezes execution when an unprivileged IPC API call is made with spurious data. On version v249 and older the effect is not an assert, but stack overwriting, with the attacker controlled content. From version v250 and newer this is not possible as the safety check causes an assert instead. This IPC call was added in v239, so versions older than that are not affected. Versions 260-rc1, 259.2, 258.5, and 257.11 contain patches. No known workarounds are available.

Affected Software

1 affected component
systemd systemd>=239<257.11, >=239<258.5, >=239<259.2, >=239<260-rc1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade systemd to a version that resolves this vulnerability.

    Patch 260-rc1
  2. Upgrade

    Upgrade systemd to a version that resolves this vulnerability.

    Patch 259.2
  3. Upgrade

    Upgrade systemd to a version that resolves this vulnerability.

    Patch 258.5
  4. Upgrade

    Upgrade systemd to a version that resolves this vulnerability.

    Patch 257.11

Event History

Mar 23, 2026
Data Sourced
via Red Hat·10:02 PM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of REDHAT-BUG-2450505?

REDHAT-BUG-2450505 is considered a critical vulnerability due to the potential for execution freeze and stack overwriting.

2

How do I fix REDHAT-BUG-2450505?

To fix REDHAT-BUG-2450505, upgrade systemd to a version newer than 257.11 or 258.5 depending on your current version.

3

What versions of systemd are affected by REDHAT-BUG-2450505?

REDHAT-BUG-2450505 affects systemd versions from 239 up to 257.11, along with specific versions up to 260-rc1.

4

Can unprivileged users exploit REDHAT-BUG-2450505?

Yes, unprivileged users can exploit REDHAT-BUG-2450505 through malicious IPC API calls that provide spurious data.

5

What impact does REDHAT-BUG-2450505 have on system performance?

The impact of REDHAT-BUG-2450505 includes execution freezing or stack corruption, which could lead to system instability and denial of service.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203