Reachable assertion in systemd - CVE-2026-29111

 

Reachable assertion in systemd - CVE-2026-29111

Published: March 26, 2026


Vulnerability identifier: #VU124627
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-29111
CWE-ID: CWE-617
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to a reachable assertion. A local user can supply specially crafted input to the IPC API call and perform a denial of service attack.

Note, on version 249 and older this call will trigger a stack-based buffer overflow instead of assertion. 


Affected software

systemd
systemd (Ubuntu package)
systemd-container
systemd-debuginfo
systemd-debugsource
systemd-devel
systemd-journal-remote
systemd-udev
systemd-udev-compat
systemd-help
systemd-libs
systemd-cryptsetup
systemd-networkd
systemd-nspawn
systemd-pam
systemd-resolved
systemd-timesyncd
systemd (Red Hat package)
systemd-oomd-defaults
systemd-battery-check
systemd-boot-unsigned
systemd-bsod
systemd-pcrlock
systemd-standalone-repart
systemd-standalone-shutdown
systemd-standalone-sysusers
systemd-standalone-tmpfiles
systemd-storagetm
systemd-tests
systemd-doc
systemd-rpm-macros
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Ubuntu
openEuler
Anolis OS

How to mitigate CVE-2026-29111

Install updates from vendor's website.

systemd - addressed in versions 257.11, 258.5, 259.2
systemd (Ubuntu package) - addressed in versions 204-5ubuntu20.31+esm3, 229-4ubuntu21.31+esm4, 237-3ubuntu10.57+esm3, 245.4-4ubuntu3.24+esm3, 249.11-0ubuntu3.19, 255.4-1ubuntu8.14, 257.9-0ubuntu2.3
systemd - addressed in versions 243-89, 249-113
systemd-container - addressed in versions 243-89, 249-113
systemd-debuginfo - addressed in versions 243-89, 249-113
systemd-debugsource - addressed in versions 243-89, 249-113
systemd-devel - addressed in versions 243-89, 249-113
systemd-journal-remote - update to 243-89
systemd-udev - addressed in versions 243-89, 249-113
systemd-udev-compat - update to 243-89
systemd-help - addressed in versions 243-89, 249-113
systemd-libs - addressed in versions 243-89, 249-113
systemd-cryptsetup - update to 249-113
systemd-networkd - update to 249-113
systemd-nspawn - update to 249-113
systemd-pam - update to 249-113
systemd-resolved - update to 249-113
systemd-timesyncd - update to 249-113
systemd (Red Hat package) - addressed in versions 252-55.el9_7.9, 257-13.el10_1.3
systemd-oomd-defaults - update to 255-16
systemd - update to 255-16
systemd-battery-check - update to 255-16
systemd-boot-unsigned - update to 255-16
systemd-bsod - update to 255-16
systemd-container - update to 255-16
systemd-devel - update to 255-16
systemd-journal-remote - update to 255-16
systemd-libs - update to 255-16
systemd-pam - update to 255-16
systemd-pcrlock - update to 255-16
systemd-resolved - update to 255-16
systemd-standalone-repart - update to 255-16
systemd-standalone-shutdown - update to 255-16
systemd-standalone-sysusers - update to 255-16
systemd-standalone-tmpfiles - update to 255-16
systemd-storagetm - update to 255-16
systemd-tests - update to 255-16
systemd-udev - update to 255-16
systemd-doc - update to 255-16
systemd-rpm-macros - update to 255-16

External References

Related Security Bulletins