Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-4533-1 | systemd security update |
Mon, 27 Apr 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Systemd Project
Systemd Project systemd |
|
| CPEs | cpe:2.3:a:systemd_project:systemd:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Systemd Project
Systemd Project systemd |
Tue, 14 Apr 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 14 Apr 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Privilege Escalation via Malicious Hardware Devices in systemd udev | systemd: udev in systemd: Privilege escalation via malicious hardware devices and unsanitized kernel output |
| Weaknesses | CWE-250 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Mon, 13 Apr 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Privilege Escalation via Malicious Hardware Devices in systemd udev |
Mon, 13 Apr 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Systemd
Systemd systemd |
|
| Vendors & Products |
Systemd
Systemd systemd |
Fri, 10 Apr 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In udev in systemd before 260, local root execution can occur via malicious hardware devices and unsanitized kernel output. | |
| Weaknesses | CWE-669 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-04-14T14:40:30.611Z
Reserved: 2026-04-10T15:16:19.391Z
Link: CVE-2026-40225
Updated: 2026-04-14T14:40:23.155Z
Status : Analyzed
Published: 2026-04-10T16:16:33.287
Modified: 2026-04-27T19:00:02.210
Link: CVE-2026-40225
OpenCVE Enrichment
Updated: 2026-04-14T16:36:29Z
Debian DLA