CVE-2026-40226: Systemd Project Systemd

Medium severity, CVSS 6.4. EPSS: 0.1% chance of exploitation in the next 30 days.

In nspawn in systemd 233 through 259 before 260, an escape-to-host action can occur via a crafted optional config file.

Affected products

  • Systemd Project Systemd: from 233, before 257.12 (fixed in 257.12); from 258, before 258.6 (fixed in 258.6); from 259, before 259.4 (fixed in 259.4)

Published 2026-04-10. Last modified 2026-06-17.