UbuntuUpdates.org

Bugs fixes in "systemd"

Origin Bug number Title Date fixed
CVE CVE-2026-16742 systemd-homed contains a local privilege escalation bug via arbitrary system group addition to a local, logged in, homed-managed user 2026-09-30
CVE CVE-2026-15059 Local unprivileged users can terminate arbitrary local processes via a systemd-oomd IPC API due to a missing path traversal validation. 2026-09-30
CVE CVE-2026-15060 When systemd-machined >= v259 (or v258 with a custom `polkit` policy that allows `register-machine` access) is running on a desktop system, an unpriv 2026-09-30
Launchpad 2167504 [SRU] systemd v259.9 to resolute 2026-09-30
CVE CVE-2026-16742 systemd-homed contains a local privilege escalation bug via arbitrary system group addition to a local, logged in, homed-managed user 2026-09-30
CVE CVE-2026-15059 Local unprivileged users can terminate arbitrary local processes via a systemd-oomd IPC API due to a missing path traversal validation. 2026-09-30
CVE CVE-2026-15060 When systemd-machined >= v259 (or v258 with a custom `polkit` policy that allows `register-machine` access) is running on a desktop system, an unpriv 2026-09-30
Launchpad 2167504 [SRU] systemd v259.9 to resolute 2026-09-30
Launchpad 2157344 systemd: TEST-70-TPM2 and TEST-86-MULTI-PROFILE-UKI timeout 2026-06-25
Launchpad 2157342 systemd: TEST-45-TIMEDATE is flaky with rust coreutils 2026-06-25
Launchpad 2157344 systemd: TEST-70-TPM2 and TEST-86-MULTI-PROFILE-UKI timeout 2026-06-25
Launchpad 2157342 systemd: TEST-45-TIMEDATE is flaky with rust coreutils 2026-06-25
Launchpad 2150773 Slowness on UC26 on daemon-reload requests 2026-06-09
Launchpad 2148619 `cloud-init` local datasource discovery takes ~30s to complete 2026-06-09
Launchpad 2150773 Slowness on UC26 on daemon-reload requests 2026-06-09
Launchpad 2148619 `cloud-init` local datasource discovery takes ~30s to complete 2026-06-09
CVE CVE-2026-40226 In nspawn in systemd 233 through 259 before 260, an escape-to-host action can occur via a crafted optional config file. 2026-06-08
CVE CVE-2023-7008 A vulnerability was found in systemd-resolved. This issue may allow systemd-resolved to accept records of DNSSEC-signed domains even when they have n 2026-06-08
CVE CVE-2026-40226 In nspawn in systemd 233 through 259 before 260, an escape-to-host action can occur via a crafted optional config file. 2026-06-08
CVE CVE-2023-7008 A vulnerability was found in systemd-resolved. This issue may allow systemd-resolved to accept records of DNSSEC-signed domains even when they have n 2026-06-08



About   -   Send Feedback to @ubuntu_updates