{"id":"SUSE-SU-2026:0990-1","summary":"Security update for systemd","details":"This update for systemd fixes the following issues:\n\n- CVE-2026-4105: privilege escalation due to improper access control in RegisterMachine D-Bus method (bsc#1259650).\n- CVE-2026-29111: local unprivileged user can trigger an assert in systemd (bsc#1259418).\n- udev: check for invalid chars in various fields received from the kernel (bsc#1259697).  \n\nChangelog:\n\n- 566517ffcb machined: reject invalid class types when registering machines\n- abbdd89d78 udev: fix review mixup\n- c9cedd26be udev-builtin-net-id: print cescaped bad attributes\n- c0f4ec3db9 udev: ensure tag parsing stays within bounds\n- 38afcb73cc udev: ensure there is space for trailing NUL before calling sprintf\n- a64247de62 udev: check for invalid chars in various fields received from the kernel\n- ecce32966e core/cgroup: avoid one unnecessary strjoina()\n- 6abd2b5bd2 core: validate input cgroup path more prudently\n- 2d7d93d6c1 alloc-util: add strdupa_safe() + strndupa_safe() and use it everywhere\n","modified":"2026-03-25T08:31:38.208161Z","published":"2026-03-24T07:22:51Z","related":["CVE-2026-29111","CVE-2026-4105"],"upstream":["CVE-2026-29111","CVE-2026-4105"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20260990-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259418"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259650"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259697"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-29111"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-4105"}],"affected":[{"package":{"name":"systemd","ecosystem":"SUSE:Linux Enterprise Micro 5.2","purl":"pkg:rpm/suse/systemd&distro=SUSE%20Linux%20Enterprise%20Micro%205.2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"246.16-150300.7.65.1"}]}],"ecosystem_specific":{"binaries":[{"libudev1":"246.16-150300.7.65.1","systemd-container":"246.16-150300.7.65.1","systemd-journal-remote":"246.16-150300.7.65.1","systemd-sysvinit":"246.16-150300.7.65.1","systemd":"246.16-150300.7.65.1","udev":"246.16-150300.7.65.1","libsystemd0":"246.16-150300.7.65.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:0990-1.json"}}],"schema_version":"1.7.5"}