Known Vulnerabilities for Systemd by Systemd Project
Listed below are 10 of the newest known vulnerabilities associated with "Systemd" by "Systemd Project".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-54231 json | A content injection vulnerability was found in the ABRT post-create event handler scripts in libreport. The event script quer... | Not Provided | 2026-06-13 | 2026-06-13 |
| CVE-2026-46279 json | In the Linux kernel, the following vulnerability has been resolved: mm/alloc_tag: clear codetag for pages allocated before p... | Not Provided | 2026-06-08 | 2026-06-08 |
| CVE-2026-46223 json | In the Linux kernel, the following vulnerability has been resolved: cgroup: Defer css percpu_ref kill on rmdir until cgroup ... | Not Provided | 2026-05-28 | 2026-05-28 |
| CVE-2026-45549 json | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, agent_a... | Not Provided | 2026-06-10 | 2026-06-10 |
| CVE-2026-43294 json | In the Linux kernel, the following vulnerability has been resolved: drm: renesas: rz-du: mipi_dsi: fix kernel panic when reb... | Not Provided | 2026-05-08 | 2026-05-11 |
| CVE-2026-41489 json | Pi-hole is a DNS sinkhole that protects devices from unwanted content without installing any client-side software. From 6.0 t... | Not Provided | 2026-05-11 | 2026-05-13 |
| CVE-2026-40228 json | In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a "logger -p emerg" ... | Not Provided | 2026-04-10 | 2026-05-05 |
| CVE-2026-40227 json | In systemd 260 before 261, a local unprivileged user can trigger an assert via an IPC API call with an array or map that has ... | Not Provided | 2026-04-10 | 2026-04-14 |
| CVE-2026-40226 json | In nspawn in systemd 233 through 259 before 260, an escape-to-host action can occur via a crafted optional config file. | Not Provided | 2026-04-10 | 2026-04-14 |
| CVE-2026-40225 json | In udev in systemd before 260, local root execution can occur via malicious hardware devices and unsanitized kernel output. | Not Provided | 2026-04-10 | 2026-04-14 |