6.7
/ 10
MEDIUM
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
Description
In systemd 259 before 260, there is local privilege escalation in systemd-machined because varlink can be used to reach the root namespace.
Basic Information
ID
CVE-2026-40224
Source
mitre
Published
Apr 10, 2026 at 15:14
Modified
Apr 10, 2026 at 18:13
Affected Product
Vendor
systemd
Product
systemd
Version
259
Affected Versions
systemd systemd 259