CVE-2026-40225

EUVD-2026-21399
In udev in systemd before 260, local root execution can occur via malicious hardware devices and unsanitized kernel output.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.4 MEDIUM
PHYSICAL
HIGH
NONE
CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 4.17%
Affected Products (NVD)
VendorProductVersion
systemd_projectsystemd
𝑥
< 257.13
systemd_projectsystemd
258 ≤
𝑥
< 258.7
systemd_projectsystemd
259 ≤
𝑥
< 259.5
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
systemd
bookworm
252.39-1~deb12u2
fixed
bookworm (security)
vulnerable
bullseye
vulnerable
bullseye (security)
247.3-7+deb11u8
fixed
forky
261.2-1
fixed
sid
261.2-1
fixed
trixie
257.13-1~deb13u1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
systemd
bionic
not-affected
focal
Fixed 245.4-4ubuntu3.24+esm3
released
jammy
Fixed 249.11-0ubuntu3.19
released
noble
Fixed 255.4-1ubuntu8.14
released
questing
Fixed 257.9-0ubuntu2.3
released
resolute
not-affected
trusty
not-affected
xenial
not-affected
Azure Linux logo
Azure Linux Releases
Azure Package
Release
systemd
Azure Linux 3.0
0:255-30.azl3
fixed