Upstream information

CVE-2026-40227 at MITRE

Description

In systemd 260 before 261, a local unprivileged user can trigger an assert via an IPC API call with an array or map that has a null element.

SUSE information

Overall state of this security issue: Does not affect SUSE products

SUSE Bugzilla entry: 1261980 [RESOLVED / INVALID]

No SUSE Security Announcements cross referenced.


SUSE Timeline for this CVE

CVE page created: Fri Apr 10 20:29:47 2026
CVE page last modified: Fri May 8 12:08:58 2026