Upstream information

CVE-2026-40224 at MITRE

Description

In systemd 259 before 260, there is local privilege escalation in systemd-machined because varlink can be used to reach the root namespace.

SUSE information

Overall state of this security issue: Does not affect SUSE products

SUSE Bugzilla entry: 1261978 [NEW]

No SUSE Security Announcements cross referenced.


SUSE Timeline for this CVE

CVE page created: Fri Apr 10 20:29:46 2026
CVE page last modified: Fri May 8 12:08:58 2026