CVE-2026-29111
published 2026-03-23CVE-2026-29111: systemd, a system and service manager, (as PID 1) hits an assert and freezes execution when an unprivileged IPC API call is made with spurious data. On version…
PriorityP425medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.12%
2.3th percentile
systemd, a system and service manager, (as PID 1) hits an assert and freezes execution when an unprivileged IPC API call is made with spurious data. On version v249 and older the effect is not an assert, but stack overwriting, with the attacker controlled content. From version v250 and newer this is not possible as the safety check causes an assert instead. This IPC call was added in v239, so versions older than that are not affected. Versions 260-rc1, 259.2, 258.5, and 257.11 contain patches. No known workarounds are available.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | systemd | < systemd 260~rc2-1 (forky) | systemd 260~rc2-1 (forky) |
| msrc | azl3_systemd-bootstrap_250.3-18_on_azure_linux_3.0 | — | — |
| msrc | azl3_systemd_255-26_on_azure_linux_3.0 | — | — |
| msrc | cbl2_systemd-bootstrap_250.3-13_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_systemd_250.3-23_on_cbl_mariner_2.0 | — | — |
| systemd | systemd | — | — |
| systemd | systemd | — | — |
| systemd | systemd | — | — |
| systemd_project | systemd | >= 0 < 260~rc2-1 | 260~rc2-1 |
| systemd_project | systemd | >= 0 < 249.11-0ubuntu3.19 | 249.11-0ubuntu3.19 |
| systemd_project | systemd | >= 0 < 255.4-1ubuntu8.14 | 255.4-1ubuntu8.14 |
| systemd_project | systemd | >= 0 < 257.9-0ubuntu2.3 | 257.9-0ubuntu2.3 |
| systemd_project | systemd | >= 0 < 204-5ubuntu20.31+esm3 | 204-5ubuntu20.31+esm3 |
| systemd_project | systemd | >= 0 < 229-4ubuntu21.31+esm4 | 229-4ubuntu21.31+esm4 |
| systemd_project | systemd | >= 0 < 237-3ubuntu10.57+esm3 | 237-3ubuntu10.57+esm3 |
| systemd_project | systemd | >= 0 < 245.4-4ubuntu3.24+esm3 | 245.4-4ubuntu3.24+esm3 |
| systemd_project | systemd | >= 239 < 257.11 | 257.11 |
| systemd_project | systemd | >= 258 < 258.5 | 258.5 |
| systemd_project | systemd | >= 259 < 259.2 | 259.2 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
systemd: systemd: Arbitrary code execution or Denial of Service via spurious IPC API call data
vendor_redhat·2026-03-23·CVSS 5.5
CVE-2026-29111 [MEDIUM] CWE-1287 systemd: systemd: Arbitrary code execution or Denial of Service via spurious IPC API call data
systemd: systemd: Arbitrary code execution or Denial of Service via spurious IPC API call data
systemd, a system and service manager, (as PID 1) hits an assert and freezes execution when an unprivileged IPC API call is made with spurious data. On version v249 and older the effect is not an assert, but stack overwriting, with the attacker controlled content. From version v250 and newer this is not possible as the safety check causes an assert instead. This IPC call was added in v239, so versions older than that are not affected. Versions 260-rc1, 259.2, 258.5, and 257.11 contain patches. No known workarounds are available.
A flaw was found in systemd, a system and service manager. An unprivileged user can exploit this vulnerability by making an Inter-Process Communication (IPC) API call w
Ubuntu
systemd vulnerabilities
vendor_ubuntu·2026-03-23·CVSS 5.5
CVE-2026-29111 [MEDIUM] systemd vulnerabilities
Title: systemd vulnerabilities
Summary: Several security issues were fixed in systemd.
It was discovered that systemd incorrectly handled certain cgroup paths.
A local attacker could possibly use this issue to cause systemd to crash,
resulting in a denial of service. (CVE-2026-29111)
It was discovered that the systemd udev component incorrectly handled
certain fields received from the kernel. An attacker with a malicious
device could possibly use this issue to execute arbitrary code as an
administrator (root).
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Ubuntu
systemd vulnerabilities
vendor_ubuntu·2026-03-23·CVSS 5.5
CVE-2026-29111 [MEDIUM] systemd vulnerabilities
Title: systemd vulnerabilities
Summary: Several security issues were fixed in systemd.
USN-8119-1 fixed vulnerabilities in systemd. This update provides the
corresponding updates for Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04
LTS, and Ubuntu 20.04 LTS.
Original advisory details:
It was discovered that systemd incorrectly handled certain cgroup paths. A
local attacker could possibly use this issue to cause systemd to crash,
resulting in a denial of service. This issue only affected Ubuntu 20.04
LTS. (CVE-2026-29111)
It was discovered that the systemd udev component incorrectly handled
certain fields received from the kernel. An attacker with a malicious
device could possibly use this issue to execute arbitrary code as an
administrator (root).
Instructions: After a standard syste
Microsoft
systemd: Local unprivileged user can trigger an assert
vendor_msrc·2026-03-10·CVSS 5.5
CVE-2026-29111 [MEDIUM] CWE-269 systemd: Local unprivileged user can trigger an assert
systemd: Local unprivileged user can trigger an assert
Mariner: Mariner
GitHub_M: GitHub_M
Customer Action Required: Yes
Debian
CVE-2026-29111: systemd - systemd, a system and service manager, (as PID 1) hits an assert and freezes exe...
vendor_debian·2026·CVSS 5.5
CVE-2026-29111 [MEDIUM] CVE-2026-29111: systemd - systemd, a system and service manager, (as PID 1) hits an assert and freezes exe...
systemd, a system and service manager, (as PID 1) hits an assert and freezes execution when an unprivileged IPC API call is made with spurious data. On version v249 and older the effect is not an assert, but stack overwriting, with the attacker controlled content. From version v250 and newer this is not possible as the safety check causes an assert instead. This IPC call was added in v239, so versions older than that are not affected. Versions 260-rc1, 259.2, 258.5, and 257.11 contain patches. No known workarounds are available.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 260~rc2-1)
sid: resolved (fixed in 260~rc2-1)
trixie: open
OSV
CVE-2026-29111: systemd, a system and service manager, (as PID 1) hits an assert and freezes execution when an unprivileged IPC API call is made with spurious data
osv·2026-03-23·CVSS 5.5
CVE-2026-29111 [MEDIUM] CVE-2026-29111: systemd, a system and service manager, (as PID 1) hits an assert and freezes execution when an unprivileged IPC API call is made with spurious data
systemd, a system and service manager, (as PID 1) hits an assert and freezes execution when an unprivileged IPC API call is made with spurious data. On version v249 and older the effect is not an assert, but stack overwriting, with the attacker controlled content. From version v250 and newer this is not possible as the safety check causes an assert instead. This IPC call was added in v239, so versions older than that are not affected. Versions 260-rc1, 259.2, 258.5, and 257.11 contain patches. No known workarounds are available.
OSV
systemd vulnerabilities
osv·2026-03-23·CVSS 5.5
CVE-2026-29111 [MEDIUM] systemd vulnerabilities
systemd vulnerabilities
USN-8119-1 fixed vulnerabilities in systemd. This update provides the
corresponding updates for Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04
LTS, and Ubuntu 20.04 LTS.
Original advisory details:
It was discovered that systemd incorrectly handled certain cgroup paths. A
local attacker could possibly use this issue to cause systemd to crash,
resulting in a denial of service. This issue only affected Ubuntu 20.04
LTS. (CVE-2026-29111)
It was discovered that the systemd udev component incorrectly handled
certain fields received from the kernel. An attacker with a malicious
device could possibly use this issue to execute arbitrary code as an
administrator (root).
OSV
systemd vulnerabilities
osv·2026-03-23·CVSS 5.5
CVE-2026-29111 [MEDIUM] systemd vulnerabilities
systemd vulnerabilities
It was discovered that systemd incorrectly handled certain cgroup paths.
A local attacker could possibly use this issue to cause systemd to crash,
resulting in a denial of service. (CVE-2026-29111)
It was discovered that the systemd udev component incorrectly handled
certain fields received from the kernel. An attacker with a malicious
device could possibly use this issue to execute arbitrary code as an
administrator (root).
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-29111 NetworkManager: systemd: Arbitrary code execution or Denial of Service via spurious IPC API call data [fedora-42]
bugzilla·2026-03-24·CVSS 5.5
CVE-2026-29111 [MEDIUM] CVE-2026-29111 NetworkManager: systemd: Arbitrary code execution or Denial of Service via spurious IPC API call data [fedora-42]
CVE-2026-29111 NetworkManager: systemd: Arbitrary code execution or Denial of Service via spurious IPC API call data [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from releases that are no longer
maintained. At that time this bug will be closed as EOL if it remains open with a
'version' of '42'.
Package Maintainer: If you wish for this bug to remain open because you
plan to fix it in
Bugzilla
CVE-2026-29111 rpm-ostree: systemd: Arbitrary code execution or Denial of Service via spurious IPC API call data [fedora-42]
bugzilla·2026-03-24·CVSS 5.5
CVE-2026-29111 [MEDIUM] CVE-2026-29111 rpm-ostree: systemd: Arbitrary code execution or Denial of Service via spurious IPC API call data [fedora-42]
CVE-2026-29111 rpm-ostree: systemd: Arbitrary code execution or Denial of Service via spurious IPC API call data [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from releases that are no longer
maintained. At that time this bug will be closed as EOL if it remains open with a
'version' of '42'.
Package Maintainer: If you wish for this bug to remain open because you
plan to fix it in a cu
Bugzilla
CVE-2026-29111 systemd: systemd: Arbitrary code execution or Denial of Service via spurious IPC API call data
bugzilla·2026-03-23·CVSS 5.5
CVE-2026-29111 [MEDIUM] CVE-2026-29111 systemd: systemd: Arbitrary code execution or Denial of Service via spurious IPC API call data
CVE-2026-29111 systemd: systemd: Arbitrary code execution or Denial of Service via spurious IPC API call data
systemd, a system and service manager, (as PID 1) hits an assert and freezes execution when an unprivileged IPC API call is made with spurious data. On version v249 and older the effect is not an assert, but stack overwriting, with the attacker controlled content. From version v250 and newer this is not possible as the safety check causes an assert instead. This IPC call was added in v239, so versions older than that are not affected. Versions 260-rc1, 259.2, 258.5, and 257.11 contain patches. No known workarounds are available.
Discussion:
Per the description of the vulnerability: https://github.com/systemd/systemd/security/advisories/GHSA-gx6q-6f99-m764
NetworkManager is not
Wiz
CVE-2026-29111 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.5
CVE-2026-29111 [MEDIUM] CVE-2026-29111 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-29111 :
Wolfi vulnerability analysis and mitigation
systemd, a system and service manager, (as PID 1) hits an assert and freezes execution when an unprivileged IPC API call is made with spurious data. On version v249 and older the effect is not an assert, but stack overwriting, with the attacker controlled content. From version v250 and newer this is not possible as the safety check causes an assert instead. This IPC call was added in v239, so versions older than that are not affected. Versions 260-rc1, 259.2, 258.5, and 257.11 contain patches. No known workarounds are available.
Source : NVD
## 5.5
Score
Published March 23, 2026
Severity MEDIUM
CNA Score 5.5
Affected Technologies
Wolfi
Chainguard
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Da
https://github.com/systemd/systemd/commit/1d22f706bd04f45f8422e17fbde3f56ece17758ahttps://github.com/systemd/systemd/commit/20021e7686426052e3a7505425d7e12085feb2a6https://github.com/systemd/systemd/commit/21167006574d6b83813c7596759b474f56562412https://github.com/systemd/systemd/commit/3cee294fe8cf4fa0eff933ab21416d099942cabdhttps://github.com/systemd/systemd/commit/42aee39107fbdd7db1ccd402a2151822b2805e9fhttps://github.com/systemd/systemd/commit/54588d2dedff54bfb6036670820650e4ea74628fhttps://github.com/systemd/systemd/commit/7ac3220213690e8a8d6d2a6e81e43bd1dce01d69https://github.com/systemd/systemd/commit/80acea4ef80a4bb78560ed970c34952299b890d6https://github.com/systemd/systemd/commit/b5fd14693057e5f2c9b4a49603be64ec3608ff6chttps://github.com/systemd/systemd/commit/efa6ba2ab625aaa160ac435a09e6482fc63bdbe8https://github.com/systemd/systemd/security/advisories/GHSA-gx6q-6f99-m764
2026-03-23
Published