CVE-2026-40225: Systemd Project Systemd

Medium severity, CVSS 6.4. EPSS: 0.2% chance of exploitation in the next 30 days.

In udev in systemd before 260, local root execution can occur via malicious hardware devices and unsanitized kernel output.

Affected products

  • Systemd Project Systemd: before 257.13 (fixed in 257.13); from 258, before 258.7 (fixed in 258.7); from 259, before 259.5 (fixed in 259.5)

Published 2026-04-10. Last modified 2026-06-17.