{"id":"SUSE-SU-2026:23620-1","summary":"Security update for systemd","details":"This update for systemd fixes the following issue:\n\nSecurity issue fixed:\n\n- CVE-2026-16742: `systemd-homed`: local privilege escalation due to missing home record signature verification on\n  the authentication path (bsc#1271444).\n\nNon security issue fixed:\n\n- `systemd-resolved` fails to start due to write access to `tmpfs` denied (bsc#1237515).\n","modified":"2026-09-29T18:24:02.639688318Z","published":"2026-09-03T20:31:34Z","related":["CVE-2026-16742","CVE-2026-29111","CVE-2026-40226","CVE-2026-4105"],"upstream":["CVE-2026-16742","CVE-2026-29111","CVE-2026-40226","CVE-2026-4105"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-202623620-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1237515"},{"type":"REPORT","url":"https://bugzilla.suse.com/1254924"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259418"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259650"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261400"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271444"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-16742"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-29111"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-40226"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-4105"}],"affected":[{"package":{"name":"systemd","ecosystem":"SUSE:Linux Enterprise Server 16.0","purl":"pkg:rpm/suse/systemd&distro=SUSE%20Linux%20Enterprise%20Server%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"257.13-160000.4.1"}]}],"ecosystem_specific":{"binaries":[{"systemd-doc":"257.13-160000.4.1","systemd-homed":"257.13-160000.4.1","systemd-journal-remote":"257.13-160000.4.1","systemd-portable":"257.13-160000.4.1","libsystemd0":"257.13-160000.4.1","systemd":"257.13-160000.4.1","systemd-experimental":"257.13-160000.4.1","systemd-lang":"257.13-160000.4.1","libudev1":"257.13-160000.4.1","systemd-resolved":"257.13-160000.4.1","udev":"257.13-160000.4.1","systemd-container":"257.13-160000.4.1","systemd-devel":"257.13-160000.4.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:23620-1.json"}},{"package":{"name":"systemd","ecosystem":"SUSE:Linux Enterprise Server for SAP applications 16.0","purl":"pkg:rpm/suse/systemd&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20applications%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"257.13-160000.4.1"}]}],"ecosystem_specific":{"binaries":[{"systemd-experimental":"257.13-160000.4.1","systemd-container":"257.13-160000.4.1","systemd-doc":"257.13-160000.4.1","udev":"257.13-160000.4.1","systemd-portable":"257.13-160000.4.1","libsystemd0":"257.13-160000.4.1","systemd-journal-remote":"257.13-160000.4.1","systemd-resolved":"257.13-160000.4.1","libudev1":"257.13-160000.4.1","systemd-lang":"257.13-160000.4.1","systemd-homed":"257.13-160000.4.1","systemd":"257.13-160000.4.1","systemd-devel":"257.13-160000.4.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:23620-1.json"}}],"schema_version":"1.9.0"}