https://seclists.org/oss-sec/2026/q2/402: systemd-journald in systemd 259 does not escape characters in emerg messages that awall'd to other user's terminals
Published May 4, 2026
·Updated
Affected Software
1 affected component
systemd systemd-journald=259
Frequently Asked Questions
1
What is the severity of CVE-2026-XXXX?
The severity of CVE-2026-XXXX is classified as moderate due to the potential for user terminal information leakage.
2
How do I fix CVE-2026-XXXX?
To fix CVE-2026-XXXX, you should configure systemd-journald to escape characters in emergency messages.
3
Which systems are affected by CVE-2026-XXXX?
CVE-2026-XXXX affects systems running systemd 259, including the default configurations in Ubuntu 26.04 pre-release images and Arch Linux.
4
What features in systemd-journald contribute to CVE-2026-XXXX?
The vulnerability arises from the default settings of 'ForwardToWall=yes' and 'MaxWallLevel=emerg' in systemd-journald.
5
What potential risks does CVE-2026-XXXX pose to users?
CVE-2026-XXXX poses risks of information leakage through unescaped emergency messages displayed on other users' terminals.