CVE-2026-40226

Updated on 10 Apr 2026

Severity

6.4 Medium severity

Details

CVSS score
6.4
CVSS vector
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

Overview

About vulnerability

In nspawn in systemd 233 through 259 before 260, an escape-to-host action can occur via a crafted optional config file.

Details

Affected packages:
systemd @ 239 (+7 more)

Fixes