CVE-2026-40226
Received
Received - Intake
Escape-to-Host Vulnerability in systemd nspawn via Config File
Publication date: 2026-04-10
Last updated on: 2026-04-17
Assigner: MITRE
Description
Description
In nspawn in systemd 233 through 259 before 260, an escape-to-host action can occur via a crafted optional config file.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| systemd_project | systemd | From 233 (inc) to 257.12 (exc) |
| systemd_project | systemd | From 258 (inc) to 258.6 (exc) |
| systemd_project | systemd | From 259 (inc) to 259.4 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-348 | The product has two different sources of the same data or information, but it uses the source that has less support for verification, is less trusted, or is less resistant to attack. |