« Volver al listado

CVE-2026-40225

Estado: AnalizadaMedia (6.4)—

In udev in systemd before 260, local root execution can occur via malicious hardware devices and unsanitized kernel output.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-40225",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-40225",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-04-14T14:40:04.875187Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "cve@mitre.org",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.4,
          "attackVector": "PHYSICAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 0.5
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "systemd",
          "product": "systemd",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "260",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-04-10T16:16:33.287",
  "references": [
    {
      "url": "https://github.com/systemd/systemd/security/advisories/GHSA-vpfq-8p5f-jcqx",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "cve@mitre.org",
      "description": [
        {
          "lang": "en",
          "value": "CWE-669"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In udev in systemd before 260, local root execution can occur via malicious hardware devices and unsanitized kernel output."
    }
  ],
  "lastModified": "2026-06-17T10:44:52.950",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:systemd_project:systemd:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "77A2DC6B-8E0C-48FF-B902-E46957A06490",
              "versionEndExcluding": "257.13"
            },
            {
              "criteria": "cpe:2.3:a:systemd_project:systemd:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8A8904AE-67FB-4E18-968F-4F6ACCB4FE4D",
              "versionEndExcluding": "258.7",
              "versionStartIncluding": "258"
            },
            {
              "criteria": "cpe:2.3:a:systemd_project:systemd:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "480B9759-F527-4BFB-9502-F8E4135EBAF9",
              "versionEndExcluding": "259.5",
              "versionStartIncluding": "259"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}