Systemd Project
Systemd Project Systemd: vulnerabilidades y CVE
Systemd Project Systemd tiene 55 vulnerabilidades publicadas, 7 de ellas en los últimos 12 meses. 4 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE55
Últimos 12 meses7
Críticas4
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-40228 | Baja (3.3) | 0.14% | — | 10 abr 2026 | In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a "logger -p emerg" command is executed, if ForwardToWall=yes is set. |
| CVE-2026-40227 | Media (5.5) | 0.29% | — | 10 abr 2026 | In systemd 260 before 261, a local unprivileged user can trigger an assert via an IPC API call with an array or map that has a null element. |
| CVE-2026-40226 | Media (6.4) | 0.09% | — | 10 abr 2026 | In nspawn in systemd 233 through 259 before 260, an escape-to-host action can occur via a crafted optional config file. |
| CVE-2026-40225 | Media (6.4) | 0.21% | — | 10 abr 2026 | In udev in systemd before 260, local root execution can occur via malicious hardware devices and unsanitized kernel output. |
| CVE-2026-40224 | Alta (7.3) | 0.12% | — | 10 abr 2026 | In systemd 259 before 260, there is local privilege escalation in systemd-machined because varlink can be used to reach the root namespace. |
| CVE-2026-40223 | Media (5.5) | 0.12% | — | 10 abr 2026 | In systemd 258 before 260, a local unprivileged user can trigger an assert when a Delegate=yes and User=<unset> unit exists and is running. |
| CVE-2026-29111 | Media (5.5) | 0.17% | — | 23 mar 2026 | systemd, a system and service manager, (as PID 1) hits an assert and freezes execution when an unprivileged IPC API call is made with spurious data. On version v249 and older the effect is not an assert, but stack… |
| CVE-2025-4598 | Media (4.7) | 1.2% | — | 30 may 2025 | A vulnerability was found in systemd-coredump. This flaw allows an attacker to force a SUID process to crash and replace it with a non-SUID binary to access the original's privileged process coredump, allowing the… |
| CVE-2023-7008 | Media (5.9) | 0.85% | — | 23 dic 2023 | A vulnerability was found in systemd-resolved. This issue may allow systemd-resolved to accept records of DNSSEC-signed domains even when they have no signature, allowing man-in-the-middles (or the upstream DNS… |
| CVE-2023-31439 | Media (5.3) | 0.35% | — | 13 jun 2023 | An issue was discovered in systemd 253. An attacker can modify the contents of past events in a sealed log file and then adjust the file such that checking the integrity shows no error, despite modifications. NOTE: the… |
| CVE-2023-31438 | Media (5.3) | 0.33% | — | 13 jun 2023 | An issue was discovered in systemd 253. An attacker can truncate a sealed log file and then resume log sealing such that checking the integrity shows no error, despite modifications. NOTE: the vendor reportedly sent "a… |
| CVE-2023-31437 | Media (5.3) | 0.34% | — | 13 jun 2023 | An issue was discovered in systemd 253. An attacker can modify a sealed log file such that, in some views, not all existing and sealed log messages are displayed. NOTE: the vendor reportedly sent "a reply denying that… |
| CVE-2023-26604 | Alta (7.8) | 1.1% | — | 3 mar 2023 | systemd before 247 does not adequately block local privilege escalation for some Sudo configurations, e.g., plausible sudoers files in which the "systemctl status" command may be executed. Specifically, systemd does not… |
| CVE-2022-4415 | Media (5.5) | 0.85% | — | 11 ene 2023 | A vulnerability was found in systemd. This security flaw can cause a local information leak due to systemd-coredump not respecting the fs.suid_dumpable kernel setting. |
| CVE-2022-45873 | Media (5.5) | 0.27% | — | 23 nov 2022 | systemd 250 and 251 allows local users to achieve a systemd-coredump deadlock by triggering a crash that has a long backtrace. This occurs in parse_elf_object in shared/elf-util.c. The exploitation methodology is to… |
| CVE-2022-3821 | Media (5.5) | 0.42% | — | 8 nov 2022 | An off-by-one Error issue was discovered in Systemd in format_timespan() function of time-util.c. An attacker could supply specific values for time and accuracy that leads to buffer overrun in format_timespan(), leading… |
| CVE-2022-2526 | Crítica (9.8) | 1.3% | — | 9 sept 2022 | A use-after-free vulnerability was found in systemd. This issue occurs due to the on_stream_io() function and dns_stream_complete() function in 'resolved-dns-stream.c' not incrementing the reference counting for the… |
| CVE-2021-3997 | Media (5.5) | 1.7% | — | 23 ago 2022 | A flaw was found in systemd. An uncontrolled recursion in systemd-tmpfiles may lead to a denial of service at boot time when too many nested directories are created in /tmp. |
| CVE-2021-33910 | Media (5.5) | 8.8% | — | 20 jul 2021 | basic/unit-name.c in systemd prior to 246.15, 247.8, 248.5, and 249.1 has a Memory Allocation with an Excessive Size Value (involving strdupa and alloca for a pathname controlled by a local attacker) that results in an… |
| CVE-2020-13529 | Media (6.1) | 1.4% | — | 10 may 2021 | An exploitable denial-of-service vulnerability exists in Systemd 245. A specially crafted DHCP FORCERENEW packet can cause a server running the DHCP client to be vulnerable to a DHCP ACK spoofing attack. An attacker can… |
| CVE-2020-13776 | Media (6.7) | 0.46% | — | 3 jun 2020 | systemd through v245 mishandles numerical usernames such as ones composed of decimal digits or 0x followed by hex digits, as demonstrated by use of root privileges when privileges of the 0x0 user account were intended.… |
| CVE-2020-1712 | Alta (7.8) | 0.46% | — | 31 mar 2020 | A heap use-after-free vulnerability was found in systemd before version v245-rc1, where asynchronous Polkit queries are performed while handling dbus messages. A local unprivileged attacker can abuse this flaw to crash… |
| CVE-2012-1101 | Media (5.5) | 0.40% | — | 11 mar 2020 | systemd 37-1 does not properly handle non-existent services, which causes a denial of service (failure of login procedure). |
| CVE-2019-20386 | Baja (2.4) | 0.43% | — | 21 ene 2020 | An issue was discovered in button_open in login/logind-button.c in systemd before 243. When executing the udevadm trigger command, a memory leak may occur. |
| CVE-2018-21029 | Crítica (9.8) | 3.1% | — | 30 oct 2019 | systemd 239 through 245 accepts any certificate signed by a trusted certificate authority for DNS Over TLS. Server Name Indication (SNI) is not sent, and there is no hostname validation with the GnuTLS backend. NOTE:… |
| CVE-2019-15718 | Media (4.4) | 0.51% | — | 4 sept 2019 | In systemd 240, bus_open_system_watch_bind_with_description in shared/bus-util.c (as used by systemd-resolved to connect to the system D-Bus instance), calls sd_bus_set_trusted, which disables access controls for… |
| CVE-2018-20839 | Media (4.3) | 2.5% | — | 17 may 2019 | systemd 242 changes the VT1 mode upon a logout, which allows attackers to read cleartext passwords in certain circumstances, such as watching a shutdown, or using Ctrl-Alt-F1 and Ctrl-Alt-F2. This occurs because the… |
| CVE-2019-3844 | Alta (7.8) | 0.92% | — | 26 abr 2019 | It was discovered that a systemd service that uses DynamicUser property can get new privileges through the execution of SUID binaries, which would allow to create binaries owned by the service transient group with the… |
| CVE-2019-3843 | Alta (7.8) | 0.94% | — | 26 abr 2019 | It was discovered that a systemd service that uses DynamicUser property can create a SUID/SGID binary that would be allowed to run as the transient service UID/GID even after the service is terminated. A local attacker… |
| CVE-2019-3842 | Alta (7) | 1.2% | — | 9 abr 2019 | In systemd before v242-rc4, it was discovered that pam_systemd does not properly sanitize the environment before using the XDG_SEAT variable. It is possible for an attacker, in some particular configurations, to set a… |