Local Root Execution Vulnerability in udev from Systemd
CVE-2026-40225

6.4MEDIUM

Key Information:

Vendor

Systemd

Status
Vendor
CVE Published:
10 April 2026

What is CVE-2026-40225?

A vulnerability exists in the udev component of Systemd prior to version 260, where local root execution can be exploited through malicious hardware devices. This flaw arises from unsanitized kernel output, allowing threat actors to gain elevated privileges on affected systems. It is critical for users to apply updates and implement security measures to mitigate this risk.

Affected Version(s)

systemd 0 < 260

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.