Reachable assertion in systemd - CVE-2026-29111
Published: March 26, 2026
Vulnerability details
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to a reachable assertion. A local user can supply specially crafted input to the IPC API call and perform a denial of service attack.
Note, on version 249 and older this call will trigger a stack-based buffer overflow instead of assertion.
Affected software
systemd (Ubuntu package)
systemd-container
systemd-debuginfo
systemd-debugsource
systemd-devel
systemd-journal-remote
systemd-udev
systemd-udev-compat
systemd-help
systemd-libs
systemd-cryptsetup
systemd-networkd
systemd-nspawn
systemd-pam
systemd-resolved
systemd-timesyncd
systemd (Red Hat package)
systemd-oomd-defaults
systemd-battery-check
systemd-boot-unsigned
systemd-bsod
systemd-pcrlock
systemd-standalone-repart
systemd-standalone-shutdown
systemd-standalone-sysusers
systemd-standalone-tmpfiles
systemd-storagetm
systemd-tests
systemd-doc
systemd-rpm-macros
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Ubuntu
openEuler
Anolis OS
How to mitigate CVE-2026-29111
systemd (Ubuntu package) - addressed in versions 204-5ubuntu20.31+esm3, 229-4ubuntu21.31+esm4, 237-3ubuntu10.57+esm3, 245.4-4ubuntu3.24+esm3, 249.11-0ubuntu3.19, 255.4-1ubuntu8.14, 257.9-0ubuntu2.3
systemd - addressed in versions 243-89, 249-113
systemd-container - addressed in versions 243-89, 249-113
systemd-debuginfo - addressed in versions 243-89, 249-113
systemd-debugsource - addressed in versions 243-89, 249-113
systemd-devel - addressed in versions 243-89, 249-113
systemd-journal-remote - update to 243-89
systemd-udev - addressed in versions 243-89, 249-113
systemd-udev-compat - update to 243-89
systemd-help - addressed in versions 243-89, 249-113
systemd-libs - addressed in versions 243-89, 249-113
systemd-cryptsetup - update to 249-113
systemd-networkd - update to 249-113
systemd-nspawn - update to 249-113
systemd-pam - update to 249-113
systemd-resolved - update to 249-113
systemd-timesyncd - update to 249-113
systemd (Red Hat package) - addressed in versions 252-55.el9_7.9, 257-13.el10_1.3
systemd-oomd-defaults - update to 255-16
systemd - update to 255-16
systemd-battery-check - update to 255-16
systemd-boot-unsigned - update to 255-16
systemd-bsod - update to 255-16
systemd-container - update to 255-16
systemd-devel - update to 255-16
systemd-journal-remote - update to 255-16
systemd-libs - update to 255-16
systemd-pam - update to 255-16
systemd-pcrlock - update to 255-16
systemd-resolved - update to 255-16
systemd-standalone-repart - update to 255-16
systemd-standalone-shutdown - update to 255-16
systemd-standalone-sysusers - update to 255-16
systemd-standalone-tmpfiles - update to 255-16
systemd-storagetm - update to 255-16
systemd-tests - update to 255-16
systemd-udev - update to 255-16
systemd-doc - update to 255-16
systemd-rpm-macros - update to 255-16
External References
- https://github.com/systemd/systemd/commit/1d22f706bd04f45f8422e17fbde3f56ece17758a
- https://github.com/systemd/systemd/commit/20021e7686426052e3a7505425d7e12085feb2a6
- https://github.com/systemd/systemd/commit/21167006574d6b83813c7596759b474f56562412
- https://github.com/systemd/systemd/commit/3cee294fe8cf4fa0eff933ab21416d099942cabd
- https://github.com/systemd/systemd/commit/42aee39107fbdd7db1ccd402a2151822b2805e9f
- https://github.com/systemd/systemd/commit/54588d2dedff54bfb6036670820650e4ea74628f
- https://github.com/systemd/systemd/commit/7ac3220213690e8a8d6d2a6e81e43bd1dce01d69
- https://github.com/systemd/systemd/commit/80acea4ef80a4bb78560ed970c34952299b890d6
- https://github.com/systemd/systemd/commit/b5fd14693057e5f2c9b4a49603be64ec3608ff6c
- https://github.com/systemd/systemd/commit/efa6ba2ab625aaa160ac435a09e6482fc63bdbe8
- https://github.com/systemd/systemd/security/advisories/GHSA-gx6q-6f99-m764