CVE-2026-29111
CVE-2026-29111 — systemd: Local unprivileged user can trigger an assert
systemd, a system and service manager, (as PID 1) hits an assert and freezes execution when an unprivileged IPC API call is made with spurious data. On version v249 and older the effect is not an assert, but stack overwriting, with the attacker controlled content. From version v250 and newer this is not possible as the safety check causes an assert instead. This IPC call was added in v239, so versions older than that are not affected. Versions 260-rc1, 259.2, 258.5, and 257.11 contain patches. No known workarounds are available.
Published Updated Sources: cvelistV5, GitHub_M
Triage
Is it exploited, how likely is exploitation, what does it touch, and how severe do the scoring sources call it.
Exploitation
Unreported
no source claims exploitation
EPSS
0%
chance of exploitation in 30 days
CVSS base
5.5
MEDIUM
CISA SSVC assessment
Three decision points CISA publishes for the CVEs it assesses · SSVC 2.0.3. A stakeholder decision, not a severity score.
Exploitation
None
none · proof-of-concept · active
Automatable
No
can an attacker script all four kill-chain steps
Technical impact
Partial
partial · total control of the vulnerable component
Affected scope
The catalog records vendors and products as separate lists, not pairs, so which product belongs to which vendor is not something this page can say.
Vendors (1)
Products (1)
Every base score collected
Sources score independently and disagree; each row says who scored it and under which version.
| Score | Version | Severity | Expl. | Impact | Source |
|---|---|---|---|---|---|
| 5.5 | CVSS 3.1 | MEDIUM | — | — | cvelistV5 |
Weakness & attack patterns
- CWE-269
Attack patterns reported against this CVE. The ATT&CK techniques below are inferred from its weakness class.
- T1548Abuse Elevation Control Mechanism
References
11 on the record
- github.com/systemd/systemd/security/advisories/GHSA-gx6q-6f99-m764
x_refsource_CONFIRM
- github.com/systemd/systemd/commit/1d22f706bd04f45f8422e17fbde3f56ece17758a
x_refsource_MISC
- github.com/systemd/systemd/commit/20021e7686426052e3a7505425d7e12085feb2a6
x_refsource_MISC
- github.com/systemd/systemd/commit/21167006574d6b83813c7596759b474f56562412
x_refsource_MISC
- github.com/systemd/systemd/commit/3cee294fe8cf4fa0eff933ab21416d099942cabd
x_refsource_MISC
- github.com/systemd/systemd/commit/42aee39107fbdd7db1ccd402a2151822b2805e9f
x_refsource_MISC
- github.com/systemd/systemd/commit/54588d2dedff54bfb6036670820650e4ea74628f
x_refsource_MISC
- github.com/systemd/systemd/commit/7ac3220213690e8a8d6d2a6e81e43bd1dce01d69
x_refsource_MISC
Elsewhere on this site
Not in any source we poll
Listed rather than left blank: an empty field and an unmeasured one look identical on screen, and only one is a reason to look elsewhere.
- No confirmed IOCs, IP addresses, domains, file hashes, or malware artifacts supplied.
- No organization-specific asset inventory, compensating-control status, or patch deployment evidence supplied.
- No exploit packet captures, log samples, or incident case IDs supplied.