In udev in systemd before 260, local root execution can occur via malicious hardware devices and unsanitized kernel output.
{
"cwe_ids": [
"CWE-669"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/40xxx/CVE-2026-40225.json",
"cna_assigner": "mitre"
}