Systemd Project / Systemd
56 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-40228 | systemd: systemd-journald: Unintended output to user terminals via logger command | LOW | 3.3 | Apr 10, 2026 |
| CVE-2026-40227 | systemd: systemd: Denial of Service via malicious IPC API call with null element | MEDIUM | 6.2 | Apr 10, 2026 |
| CVE-2026-40226 | systemd: systemd nspawn: Escape-to-host action via crafted config file | MEDIUM | 6.4 | Apr 10, 2026 |
| CVE-2026-40225 | systemd: udev in systemd: Privilege escalation via malicious hardware devices and unsanitized kernel output | MEDIUM | 6.4 | Apr 10, 2026 |
| CVE-2026-40224 | systemd: systemd-machined: Local privilege escalation via varlink | HIGH | 7.3 | Apr 10, 2026 |
| CVE-2026-40223 | systemd: systemd: Local unprivileged user can cause Denial of Service | MEDIUM | 5.5 | Apr 10, 2026 |
| CVE-2026-29111 | systemd: Local unprivileged user can trigger an assert | HIGH | 7.8 | Mar 23, 2026 |
| CVE-2025-4598 | Systemd-coredump: race condition that allows a local attacker to crash a suid program and gain read access to the resulting core dump | MEDIUM | 4.7 | May 30, 2025 |
| CVE-2023-7008 | Systemd-resolved: unsigned name response in signed zone is not refused when dnssec=yes | MEDIUM | 5.9 | Dec 23, 2023 |
| CVE-2023-31439 | An issue was discovered in systemd 253. An attacker can modify the contents of past events in a sealed log file and then adjust the file such that checking the… | MEDIUM | 5.3 | Jun 13, 2023 |
| CVE-2023-31438 | An issue was discovered in systemd 253. An attacker can truncate a sealed log file and then resume log sealing such that checking the integrity shows no error,… | MEDIUM | 5.3 | Jun 13, 2023 |
| CVE-2023-31437 | An issue was discovered in systemd 253. An attacker can modify a sealed log file such that, in some views, not all existing and sealed log messages are display… | MEDIUM | 5.3 | Jun 13, 2023 |
| CVE-2023-26604 | systemd: privilege escalation via the less pager | HIGH | 7.8 | Mar 3, 2023 |
| CVE-2022-4415 | systemd: local information leak due to systemd-coredump not respecting fs.suid_dumpable kernel setting | MEDIUM | 5.5 | Jan 11, 2023 |
| CVE-2022-45873 | systemd: deadlock in systemd-coredump via a crash with a long backtrace | MEDIUM | 5.5 | Nov 23, 2022 |
| CVE-2022-3821 | systemd: buffer overrun in format_timespan() function | MEDIUM | 5.5 | Nov 8, 2022 |
| CVE-2022-2526 | systemd-resolved: use-after-free when dealing with DnsStream in resolved-dns-stream.c | CRITICAL | 9.8 | Sep 9, 2022 |
| CVE-2021-3997 | systemd: Uncontrolled recursion in systemd-tmpfiles when removing files | MEDIUM | 5.5 | Aug 23, 2022 |
| CVE-2021-33910 | systemd: uncontrolled allocation on the stack in function unit_name_path_escape leads to crash | MEDIUM | 5.5 | Jul 20, 2021 |
| CVE-2020-13529 | systemd: DHCP FORCERENEW authentication not implemented can cause a system running the DHCP client to have its network reconfigured | MEDIUM | 6.1 | May 10, 2021 |
| CVE-2020-13776 | systemd: Mishandles numerical usernames beginning with decimal digits or 0x followed by hexadecimal digits | MEDIUM | 6.7 | Jun 3, 2020 |
| CVE-2020-1712 | systemd: use-after-free when asynchronous polkit queries are performed | HIGH | 7.8 | Mar 31, 2020 |
| CVE-2012-1101 | systemd 37-1 does not properly handle non-existent services, which causes a denial of service (failure of login procedure). | MEDIUM | 5.5 | Mar 11, 2020 |
| CVE-2019-20386 | systemd: memory leak in button_open() in login/logind-button.c when udev events are received | MEDIUM | 5.1 | Jan 21, 2020 |
| CVE-2018-21029 | systemd: incorrect certificate validation results in acceptance of any certificate signed by a trusted certificate authority for DNS over TLS | CRITICAL | 9.8 | Oct 30, 2019 |
Showing 1 to 25 of 56 CVEs