CVE-2026-40226

Source
https://cve.org/CVERecord?id=CVE-2026-40226
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-40226.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-40226
Aliases
  • GHSA-9mj4-rrc3-gjcx
Downstream
Related
Published
2026-04-10T15:18:10.447Z
Modified
2026-05-18T06:00:07.204882997Z
Severity
  • 6.4 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

In nspawn in systemd 233 through 259 before 260, an escape-to-host action can occur via a crafted optional config file.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/40xxx/CVE-2026-40226.json",
    "cna_assigner": "mitre",
    "cwe_ids": [
        "CWE-348"
    ]
}
References

Affected packages

Git / github.com/systemd/systemd

Affected ranges

Type
GIT
Repo
https://github.com/systemd/systemd
Events

Affected versions

Other
v233
v234
v235
v236
v237
v238
v239
v240
v241
v241-rc1
v241-rc2
v242
v242-rc1
v242-rc2
v242-rc3
v242-rc4
v243
v243-rc1
v243-rc2
v244
v244-rc1
v245
v245-rc1
v245-rc2
v246
v246-rc1
v246-rc2
v247
v247-rc1
v247-rc2
v248
v248-2
v248-rc1
v248-rc2
v248-rc3
v248-rc4
v249
v249-rc1
v249-rc2
v249-rc3
v250
v250-rc1
v250-rc2
v250-rc3
v251
v251-rc1
v251-rc2
v251-rc3
v252
v252-rc1
v252-rc2
v252-rc3
v253
v253-rc1
v253-rc2
v253-rc3
v254
v254-rc1
v254-rc2
v254-rc3
v255
v255-rc1
v255-rc2
v255-rc3
v255-rc4
v256
v256-rc1
v256-rc2
v256-rc3
v256-rc4
v257
v257-rc1
v257-rc2
v257-rc3
v258
v258-rc1
v258-rc2
v258-rc3
v258-rc4
v259
v259-rc1
v259-rc2
v259-rc3
v260-rc1
v260-rc2
v260-rc3
v260-rc4

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-40226.json"