{"id":"SUSE-SU-2026:21144-1","summary":"Security update for systemd","details":"This update for systemd fixes the following issues:\n\nUpdate to systemd v257.13:\n\nSecurity issues:\n\n- CVE-2026-4105: privilege escalation due to improper access control in RegisterMachine D-Bus method (bsc#1259650).\n- CVE-2026-29111: local unprivileged user can trigger an assert in systemd (bsc#1259418).\n- udev: local root execution via malicious hardware devices and unsanitized kernel output (bsc#1259697).\n\nNon security issues:\n\n- Avoid shipping (empty) directories and ghost files in /var (jsc#PED-14853).\n- Sign systemd-boot EFI binary on aarch64 (bsc#1258344)\n- terminal-util: stop doing 0/upper bound check in tty_is_vc() (bsc#1255326)\n\nChangelog:\n\n- 6941d92dc2 machined: reject invalid class types when registering machines (bsc#1259650 CVE-2026-4105)\n- 03bb697b8d udev: check for invalid chars in various fields received from the kernel (bsc#1259697)\n- 54588d2ded core: validate input cgroup path more prudently (bsc#1259418 CVE-2026-29111)\n- fb9d92682b terminal-util: stop doing 0/upper bound check in tty_is_vc() (bsc#1255326)\n\nFor a complete list of changes, visit:\n https://github.com/openSUSE/systemd/compare/3c53ef3ea20bd43ef587cbdfa7107aeb1ef55654...d349fc5cd4f9ee2b7884c2610647e92806d14b28\n","modified":"2026-04-22T20:09:44.951125Z","published":"2026-04-07T15:06:51Z","related":["CVE-2026-29111","CVE-2026-4105"],"upstream":["CVE-2026-29111","CVE-2026-4105"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-202621144-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1255326"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258344"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259418"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259650"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259697"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-29111"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-4105"}],"affected":[{"package":{"name":"systemd","ecosystem":"SUSE:Linux Enterprise Server 16.0","purl":"pkg:rpm/suse/systemd&distro=SUSE%20Linux%20Enterprise%20Server%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"257.13-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"libsystemd0":"257.13-160000.1.1","systemd-container":"257.13-160000.1.1","systemd-doc":"257.13-160000.1.1","systemd-experimental":"257.13-160000.1.1","systemd-homed":"257.13-160000.1.1","systemd-journal-remote":"257.13-160000.1.1","systemd-resolved":"257.13-160000.1.1","udev":"257.13-160000.1.1","libudev1":"257.13-160000.1.1","systemd-devel":"257.13-160000.1.1","systemd-lang":"257.13-160000.1.1","systemd-portable":"257.13-160000.1.1","systemd":"257.13-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:21144-1.json"}},{"package":{"name":"systemd","ecosystem":"SUSE:Linux Enterprise Server for SAP applications 16.0","purl":"pkg:rpm/suse/systemd&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20applications%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"257.13-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"libudev1":"257.13-160000.1.1","systemd-container":"257.13-160000.1.1","systemd-devel":"257.13-160000.1.1","systemd-doc":"257.13-160000.1.1","systemd-portable":"257.13-160000.1.1","libsystemd0":"257.13-160000.1.1","systemd-experimental":"257.13-160000.1.1","systemd-homed":"257.13-160000.1.1","systemd-journal-remote":"257.13-160000.1.1","systemd-lang":"257.13-160000.1.1","systemd-resolved":"257.13-160000.1.1","systemd":"257.13-160000.1.1","udev":"257.13-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:21144-1.json"}}],"schema_version":"1.7.5"}